Cryptography
This hub aggregates every CVE we track for Cryptography, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
24
CVEs tracked
2
Critical
6
High
0
In CISA KEV
Severity distribution
MEDIUM7HIGH6CRITICAL2
Monthly trend
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
1
1
1
0
1
0
3
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Cryptography.
- CVE-2026-69249python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
- CVE-2026-69248python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
- CVE-2026-69247cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
- GHSA-537c-gmf6-5ccfVulnerable OpenSSL included in cryptography wheels
- CVE-2026-39892cryptography has a buffer overflow if non-contiguous buffers were passed to APIs9.8
- CVE-2026-34073cryptography has incomplete DNS name constraint enforcement on peer names5.3
- CVE-2026-26007cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves6.5
- CVE-2024-12797RFC7250 handshakes with unauthenticated servers don't abort as expected6.3
- GHSA-h4gh-qq45-vh27pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
- CVE-2024-26130cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override7.5
- CVE-2023-50782Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-256597.5
- CVE-2024-0727PKCS12 Decoding crashes5.5
- CVE-2023-49083cryptography vulnerable to NULL-dereference when loading PKCS7 certificates5.9
- GHSA-v8gr-m533-ghj9Vulnerable OpenSSL included in cryptography wheels
- GHSA-jm77-qphf-c4w8pyca/cryptography's wheels include vulnerable OpenSSL
Product normalization is registry-driven with AI assist and human review. How it works