Cryptography.io / Cryptography
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-39892 | cryptography has a buffer overflow if non-contiguous buffers were passed to APIs | MEDIUM | 6.9 | Apr 8, 2026 |
| CVE-2026-34073 | cryptography has incomplete DNS name constraint enforcement on peer names | LOW | 1.7 | Mar 31, 2026 |
| CVE-2026-26007 | cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves | HIGH | 8.2 | Feb 10, 2026 |
| CVE-2024-26130 | cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash ove… | HIGH | 7.5 | Feb 21, 2024 |
| CVE-2023-50782 | Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659 | HIGH | 8.7 | Feb 5, 2024 |
| CVE-2023-49083 | cryptography vulnerable to NULL-dereference when loading PKCS7 certificates | HIGH | 7.5 | Nov 29, 2023 |
| CVE-2023-38325 | python-cryptography: SSH certificate encoding/parsing incompatibility with OpenSSH | HIGH | 8.7 | Jul 14, 2023 |
| CVE-2023-23931 | Cipher.update_into can corrupt memory in pyca cryptography | MEDIUM | 6.9 | Feb 7, 2023 |
| CVE-2020-36242 | python-cryptography: Large inputs for symmetric encryption can trigger integer overflow leading to buffer overflow | HIGH | 8.8 | Feb 7, 2021 |
| CVE-2020-25659 | python-cryptography: Bleichenbacher timing oracle attack against RSA decryption | HIGH | 8.2 | Jan 11, 2021 |
| CVE-2016-9243 | python-cryptography: HKDF might return an empty byte-string | HIGH | 8.7 | Mar 27, 2017 |
Showing 1 to 11 of 11 CVEs