Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3554
  • PyPI/cryptography
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees 04 Aug
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-3553
  • PyPI/cryptography
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building 04 Aug
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-3552
  • PyPI/cryptography
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing 04 Aug
  • Fix available
  • Severity - 8.2 (High)
GHSA-m2h6-j472-rp4c
  • PyPI/cryptography
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees 03 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-jwv3-5hgf-82ww
  • PyPI/cryptography
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building 03 Aug
  • Fix available
  • Severity - 8.7 (High)
GHSA-g6cj-pr64-35w5
  • PyPI/cryptography
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing 03 Aug
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-1284
  • PyPI/cryptography
Vulnerable OpenSSL included in cryptography wheels 07 Jul
  • Fix available
PYSEC-2026-1283
  • PyPI/cryptography
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack 07 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-1285
  • PyPI/cryptography
Null pointer dereference in PKCS12 parsing 07 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-800
  • PyPI/cryptography
Vulnerable OpenSSL included in cryptography wheels 07 Jul
  • Fix available
  • Severity - 7.4 (High)
GHSA-537c-gmf6-5ccf
  • PyPI/cryptography
Vulnerable OpenSSL included in cryptography wheels 15 Jun
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-36
  • PyPI/cryptography
See record for full details 08 Apr
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-p423-j2cm-9vmq
  • PyPI/cryptography
Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs 08 Apr
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-35
  • PyPI/cryptography
See record for full details 31 Mar
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-m959-cc7f-wv43
  • PyPI/cryptography
cryptography has incomplete DNS name constraint enforcement on peer names 27 Mar
  • Fix available
  • Severity - 1.7 (Low)
PYSEC-2026-2141
  • PyPI/cryptography
See record for full details 10 Feb
  • Fix available
  • Severity - 6.5 (Medium)