Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
825837
AlmaLinux
5541
Alpaquita
12789
Alpine
4417
Android
3403
Azure Linux
12016
BellSoft Hardened Containers
616
Bitnami
8525
Chainguard
10019
CleanStart
1988
CRAN
14
crates.io
2640
Debian
63410
Echo
7866
GHC
3
GIT
98321
GitHub Actions
54
Go
8603
Hackage
32
Hex
228
Julia
1655
Linux
26631
Mageia
6105
Maven
6833
MinimOS
112305
npm
226203
NuGet
1844
opam
24
openEuler
7502
openSUSE
13885
OSS-Fuzz
3978
Packagist
6822
Pub
11
PyPI
24363
Red Hat
22068
Rocky Linux
3901
Root
18886
RubyGems
4591
SUSE
22318
SwiftURL
59
TuxCare
8322
Ubuntu
59900
VSCode
20
Wolfi
7126
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3554
PyPI/cryptography
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
04 Aug
Fix available
Severity - 6.9 (Medium)
PYSEC-2026-3553
PyPI/cryptography
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
04 Aug
Fix available
Severity - 8.7 (High)
PYSEC-2026-3552
PyPI/cryptography
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
04 Aug
Fix available
Severity - 8.2 (High)
GHSA-m2h6-j472-rp4c
PyPI/cryptography
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
03 Aug
Fix available
Severity - 6.9 (Medium)
GHSA-jwv3-5hgf-82ww
PyPI/cryptography
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
03 Aug
Fix available
Severity - 8.7 (High)
GHSA-g6cj-pr64-35w5
PyPI/cryptography
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
03 Aug
Fix available
Severity - 8.2 (High)
PYSEC-2026-1284
PyPI/cryptography
Vulnerable OpenSSL included in cryptography wheels
07 Jul
Fix available
PYSEC-2026-1283
PyPI/cryptography
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
07 Jul
Fix available
Severity - 8.7 (High)
PYSEC-2026-1285
PyPI/cryptography
Null pointer dereference in PKCS12 parsing
07 Jul
Fix available
Severity - 5.5 (Medium)
PYSEC-2026-800
PyPI/cryptography
Vulnerable OpenSSL included in cryptography wheels
07 Jul
Fix available
Severity - 7.4 (High)
GHSA-537c-gmf6-5ccf
PyPI/cryptography
Vulnerable OpenSSL included in cryptography wheels
15 Jun
Fix available
Severity - 7.5 (High)
PYSEC-2026-36
PyPI/cryptography
See record for full details
08 Apr
Fix available
Severity - 9.8 (Critical)
GHSA-p423-j2cm-9vmq
PyPI/cryptography
Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs
08 Apr
Fix available
Severity - 6.9 (Medium)
PYSEC-2026-35
PyPI/cryptography
See record for full details
31 Mar
Fix available
Severity - 5.3 (Medium)
GHSA-m959-cc7f-wv43
PyPI/cryptography
cryptography has incomplete DNS name constraint enforcement on peer names
27 Mar
Fix available
Severity - 1.7 (Low)
PYSEC-2026-2141
PyPI/cryptography
See record for full details
10 Feb
Fix available
Severity - 6.5 (Medium)
Load more...
(2 pages left)
PyPI - OSV