Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2219201
AlmaLinux
5946
Alpaquita
16105
Alpine
4618
Android
3677
Azure Linux
17673
BellSoft Hardened Containers
754
Bitnami
9325
Chainguard
1035628
CleanStart
3983
CRAN
14
crates.io
2739
Debian
68648
Echo
7527
GHC
3
GIT
108492
GitHub Actions
55
Go
9245
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6232
Maven
7046
MinimOS
146695
npm
229015
NuGet
1869
opam
29
openEuler
8800
openSUSE
14498
OSS-Fuzz
4014
Packagist
7100
Pub
11
PyPI
25220
Red Hat
23413
Rocky Linux
4317
Root
19607
RubyGems
5326
SUSE
23390
SwiftURL
60
TuxCare
9662
Ubuntu
65637
VSCode
21
Wolfi
290722
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3554
PyPI/cryptography
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
04 Aug
Fix available
Severity - 6.9 (Medium)
PYSEC-2026-3553
PyPI/cryptography
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
04 Aug
Fix available
Severity - 8.7 (High)
PYSEC-2026-3552
PyPI/cryptography
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
04 Aug
Fix available
Severity - 8.2 (High)
GHSA-m2h6-j472-rp4c
PyPI/cryptography
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
03 Aug
Fix available
Severity - 6.9 (Medium)
GHSA-jwv3-5hgf-82ww
PyPI/cryptography
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
03 Aug
Fix available
Severity - 8.7 (High)
GHSA-g6cj-pr64-35w5
PyPI/cryptography
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
03 Aug
Fix available
Severity - 8.2 (High)
PYSEC-2026-1284
PyPI/cryptography
Vulnerable OpenSSL included in cryptography wheels
07 Jul
Fix available
PYSEC-2026-1283
PyPI/cryptography
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
07 Jul
Fix available
Severity - 8.7 (High)
PYSEC-2026-1285
PyPI/cryptography
Null pointer dereference in PKCS12 parsing
07 Jul
Fix available
Severity - 5.5 (Medium)
PYSEC-2026-800
PyPI/cryptography
Vulnerable OpenSSL included in cryptography wheels
07 Jul
Fix available
Severity - 7.4 (High)
GHSA-537c-gmf6-5ccf
PyPI/cryptography
Vulnerable OpenSSL included in cryptography wheels
15 Jun
Fix available
Severity - 7.5 (High)
PYSEC-2026-36
PyPI/cryptography
See record for full details
08 Apr
Fix available
Severity - 9.8 (Critical)
GHSA-p423-j2cm-9vmq
PyPI/cryptography
Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs
08 Apr
Fix available
Severity - 6.9 (Medium)
PYSEC-2026-35
PyPI/cryptography
See record for full details
31 Mar
Fix available
Severity - 5.3 (Medium)
GHSA-m959-cc7f-wv43
PyPI/cryptography
cryptography has incomplete DNS name constraint enforcement on peer names
27 Mar
Fix available
Severity - 1.7 (Low)
PYSEC-2026-2141
PyPI/cryptography
See record for full details
10 Feb
Fix available
Severity - 6.5 (Medium)
Load more...
PyPI - OSV