cryptography has 13 CVEs on record between 2023 and 2026. The median CVSS is 7.0 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.0
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
Weakness classes
Products
- cryptography 13
Worst active — by depth score
GHSA-537c-gmf6-5ccfHigh· 7.5Vulnerable OpenSSL included in cryptography wheels41CVE-2024-26130High· 7.5cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private …41CVE-2023-50782High· 7.5Python Cryptography package vulnerable to Bleichenbacher timing oracle attack41CVE-2023-38325High· 7.5cryptography mishandles SSH certificates41CVE-2023-23931Medium· 6.5Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf36
cryptography vulnerabilities
CVEs affecting cryptography, newest first. Open any entry for full detail, references, and exploit status.
13 CVEsRSS
GHSA-537c-gmf6-5ccfHigh· 7.5Vulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2026-34073Medium· 5.3cryptography has incomplete DNS name constraint enforcement on peer names
cryptography has incomplete DNS name constraint enforcement on peer names
CVE-2024-12797LowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
GHSA-h4gh-qq45-vh27Mediumpyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
CVE-2024-26130High· 7.5cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private …
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
CVE-2023-50782High· 7.5Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
CVE-2024-0727Medium· 5.5Null pointer dereference in PKCS12 parsing
Null pointer dereference in PKCS12 parsing
CVE-2023-49083Medium· 5.9cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
GHSA-v8gr-m533-ghj9LowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
GHSA-jm77-qphf-c4w8Lowpyca/cryptography's wheels include vulnerable OpenSSL
pyca/cryptography's wheels include vulnerable OpenSSL
CVE-2023-38325High· 7.5cryptography mishandles SSH certificates
cryptography mishandles SSH certificates
GHSA-5cpq-8wj7-hf2vLowVulnerable OpenSSL included in cryptography wheels
Vulnerable OpenSSL included in cryptography wheels
CVE-2023-23931Medium· 6.5Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf