Cryptography.io
Cryptography.io Cryptography: vulnerabilidades y CVE
Cryptography.io Cryptography tiene 12 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69247 | Alta (8.2) | 0.27% | — | 3 ago 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of… |
| CVE-2026-39892 | Media (6.9) | 0.76% | — | 8 abr 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g.… |
| CVE-2026-34073 | Baja (1.7) | 0.17% | — | 31 mar 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not… |
| CVE-2026-26007 | Alta (8.2) | 0.35% | — | 10 feb 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()),… |
| CVE-2024-26130 | Alta (7.5) | 0.83% | — | 21 feb 2024 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with… |
| CVE-2023-50782 | Alta (7.5) | 1.1% | — | 5 feb 2024 | A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive… |
| CVE-2023-49083 | Alta (7.5) | 0.98% | — | 29 nov 2023 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and… |
| CVE-2023-38325 | Alta (7.5) | 0.73% | — | 14 jul 2023 | The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. |
| CVE-2023-23931 | Media (6.5) | 1.3% | — | 7 feb 2023 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but… |
| CVE-2020-36242 | Crítica (9.1) | 6.7% | — | 7 feb 2021 | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet… |
| CVE-2020-25659 | Media (5.9) | 2.4% | — | 11 ene 2021 | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext. |
| CVE-2016-9243 | Alta (7.5) | 3.5% | — | 27 mar 2017 | HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size. |