cryptography
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.
Activity
- Latest release
- 21h ago
- Total releases
- 158
- Cadence
- ~20 days
- Last 12 months
- 14
Reach
- Stars
- 7.7k
Details
- License
- Apache-2.0 OR BSD-3-Clause
- First release
- Jan 08, 2014
| Version | Released | |
|---|---|---|
50.0.0
major
| ||
49.0.0
major
| ||
48.0.1
patch
| ||
48.0.0
major
1 CVE
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev | ||
47.0.0
major
1 CVE
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev | ||
46.0.7
patch
1 CVE
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev | ||
46.0.6
patch
2 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev | ||
46.0.5
patch
3 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev | ||
46.0.4
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
46.0.3
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
46.0.2
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
46.0.1
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
46.0.0
major
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
45.0.7
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
45.0.6
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
45.0.5
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
45.0.4
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
45.0.3
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
45.0.2
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
45.0.1
patch
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
45.0.0
major
4 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-39892
PYSEC-2026-36
GHSA-p423-j2cm-9vmq
Apr 08, 2026
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. Affected versions
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
+ 3 more Show less
46.0.4
46.0.5
46.0.6
Fixed in
46.0.7
References Updated May 20, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
44.0.3
patch
3 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
44.0.2
patch
3 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
44.0.1
patch
3 CVEs
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
44.0.0
major
4 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
43.0.3
patch
4 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
43.0.1
patch
4 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
43.0.0
major
5 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev | ||
42.0.8
patch
5 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev | ||
42.0.7
patch
5 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev | ||
42.0.6
patch
5 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev | ||
42.0.5
patch
5 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev | ||
42.0.4
patch
5 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev | ||
42.0.3
patch
6 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
42.0.2
patch
6 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
42.0.1
patch
7 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
42.0.0
major
7 CVEs
CVE-2024-12797
PYSEC-2026-1284
GHSA-79v4-65xg-pq4g
Jul 07, 2026
Vulnerable OpenSSL included in cryptography wheels pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 42.0.0-44.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20250211.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
+ 1 more Show less
44.0.0
Fixed in
44.0.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
41.0.7
patch
7 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
41.0.6
patch
7 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev | ||
41.0.5
patch
8 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
41.0.4
patch
8 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev | ||
41.0.3
patch
9 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev
GHSA-v8gr-m533-ghj9
Sep 21, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 2.5-41.0.3 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230908.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
+ 37 more Show less
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
Fixed in
41.0.4
References Updated Feb 04, 2026 · Source: OSV.dev | ||
41.0.2
patch
10 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev
GHSA-v8gr-m533-ghj9
Sep 21, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 2.5-41.0.3 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230908.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
+ 37 more Show less
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
Fixed in
41.0.4
References Updated Feb 04, 2026 · Source: OSV.dev
GHSA-jm77-qphf-c4w8
Aug 01, 2023
pyca/cryptography's wheels include vulnerable OpenSSL
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.8-41.0.2 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230731.txt, https://www.openssl.org/news/secadv/20230719.txt, and https://www.openssl.org/news/secadv/20230714.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
+ 88 more Show less
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
Fixed in
41.0.3
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
41.0.1
patch
11 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev
GHSA-v8gr-m533-ghj9
Sep 21, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 2.5-41.0.3 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230908.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
+ 37 more Show less
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
Fixed in
41.0.4
References Updated Feb 04, 2026 · Source: OSV.dev
GHSA-jm77-qphf-c4w8
Aug 01, 2023
pyca/cryptography's wheels include vulnerable OpenSSL
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.8-41.0.2 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230731.txt, https://www.openssl.org/news/secadv/20230719.txt, and https://www.openssl.org/news/secadv/20230714.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
+ 88 more Show less
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
Fixed in
41.0.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-38325
GHSA-cf7p-gm2m-833m
PYSEC-2023-112
Jul 14, 2023
cryptography mishandles SSH certificates
High
Network
Low
None
None
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. Affected versions
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
Fixed in
41.0.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
41.0.0
major
11 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev
GHSA-v8gr-m533-ghj9
Sep 21, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 2.5-41.0.3 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230908.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
+ 37 more Show less
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
Fixed in
41.0.4
References Updated Feb 04, 2026 · Source: OSV.dev
GHSA-jm77-qphf-c4w8
Aug 01, 2023
pyca/cryptography's wheels include vulnerable OpenSSL
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.8-41.0.2 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230731.txt, https://www.openssl.org/news/secadv/20230719.txt, and https://www.openssl.org/news/secadv/20230714.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
+ 88 more Show less
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
Fixed in
41.0.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-38325
GHSA-cf7p-gm2m-833m
PYSEC-2023-112
Jul 14, 2023
cryptography mishandles SSH certificates
High
Network
Low
None
None
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. Affected versions
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
Fixed in
41.0.2
References
Updated Feb 04, 2026 · Source: OSV.dev | ||
40.0.2
patch
12 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev
GHSA-v8gr-m533-ghj9
Sep 21, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 2.5-41.0.3 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230908.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
+ 37 more Show less
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
Fixed in
41.0.4
References Updated Feb 04, 2026 · Source: OSV.dev
GHSA-jm77-qphf-c4w8
Aug 01, 2023
pyca/cryptography's wheels include vulnerable OpenSSL
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.8-41.0.2 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230731.txt, https://www.openssl.org/news/secadv/20230719.txt, and https://www.openssl.org/news/secadv/20230714.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
+ 88 more Show less
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
Fixed in
41.0.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-38325
GHSA-cf7p-gm2m-833m
PYSEC-2023-112
Jul 14, 2023
cryptography mishandles SSH certificates
High
Network
Low
None
None
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. Affected versions
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
Fixed in
41.0.2
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-5cpq-8wj7-hf2v
Jun 02, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.5-40.0.2 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://www.openssl.org/news/secadv/20230530.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 95 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
Fixed in
41.0.0
References Updated Feb 04, 2026 · Source: OSV.dev | ||
40.0.1
patch
12 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev
GHSA-v8gr-m533-ghj9
Sep 21, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 2.5-41.0.3 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230908.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
+ 37 more Show less
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
Fixed in
41.0.4
References Updated Feb 04, 2026 · Source: OSV.dev
GHSA-jm77-qphf-c4w8
Aug 01, 2023
pyca/cryptography's wheels include vulnerable OpenSSL
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.8-41.0.2 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230731.txt, https://www.openssl.org/news/secadv/20230719.txt, and https://www.openssl.org/news/secadv/20230714.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
+ 88 more Show less
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
Fixed in
41.0.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-38325
GHSA-cf7p-gm2m-833m
PYSEC-2023-112
Jul 14, 2023
cryptography mishandles SSH certificates
High
Network
Low
None
None
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. Affected versions
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
Fixed in
41.0.2
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-5cpq-8wj7-hf2v
Jun 02, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.5-40.0.2 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://www.openssl.org/news/secadv/20230530.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 95 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
Fixed in
41.0.0
References Updated Feb 04, 2026 · Source: OSV.dev | ||
40.0.0
major
12 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev
GHSA-v8gr-m533-ghj9
Sep 21, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 2.5-41.0.3 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230908.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
+ 37 more Show less
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
Fixed in
41.0.4
References Updated Feb 04, 2026 · Source: OSV.dev
GHSA-jm77-qphf-c4w8
Aug 01, 2023
pyca/cryptography's wheels include vulnerable OpenSSL
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.8-41.0.2 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230731.txt, https://www.openssl.org/news/secadv/20230719.txt, and https://www.openssl.org/news/secadv/20230714.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
+ 88 more Show less
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
Fixed in
41.0.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-38325
GHSA-cf7p-gm2m-833m
PYSEC-2023-112
Jul 14, 2023
cryptography mishandles SSH certificates
High
Network
Low
None
None
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. Affected versions
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
Fixed in
41.0.2
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-5cpq-8wj7-hf2v
Jun 02, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.5-40.0.2 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://www.openssl.org/news/secadv/20230530.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 95 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
Fixed in
41.0.0
References Updated Feb 04, 2026 · Source: OSV.dev | ||
39.0.2
patch
11 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev
GHSA-v8gr-m533-ghj9
Sep 21, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 2.5-41.0.3 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230908.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
+ 37 more Show less
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
Fixed in
41.0.4
References Updated Feb 04, 2026 · Source: OSV.dev
GHSA-jm77-qphf-c4w8
Aug 01, 2023
pyca/cryptography's wheels include vulnerable OpenSSL
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.8-41.0.2 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230731.txt, https://www.openssl.org/news/secadv/20230719.txt, and https://www.openssl.org/news/secadv/20230714.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
+ 88 more Show less
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
Fixed in
41.0.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-5cpq-8wj7-hf2v
Jun 02, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.5-40.0.2 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://www.openssl.org/news/secadv/20230530.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 95 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
Fixed in
41.0.0
References Updated Feb 04, 2026 · Source: OSV.dev | ||
39.0.1
patch
11 CVEs
CVE-2023-50782
PYSEC-2026-1283
GHSA-3ww4-gg4f-jr7f
Jul 07, 2026
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
High
Network
Low
None
None
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 109 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
Fixed in
42.0.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-0727
PYSEC-2026-1285
GHSA-9v9h-cgj8-h64p
Jul 07, 2026
Null pointer dereference in PKCS12 parsing
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 111 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
Fixed in
42.0.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-537c-gmf6-5ccf
Jun 15, 2026
Vulnerable OpenSSL included in cryptography wheels
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 137 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
46.0.6
46.0.7
47.0.0
48.0.0
Fixed in
48.0.1
References Updated Jun 16, 2026 · Source: OSV.dev
CVE-2026-34073
PYSEC-2026-35
GHSA-m959-cc7f-wv43
Mar 31, 2026
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 139 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
46.0.5
Fixed in
46.0.6
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-26007
PYSEC-2026-2141
GHSA-r6ph-v2qm-q3c2
Feb 10, 2026
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5. Affected versions
0.1
0.2
0.2.1
0.2.2
0.3
0.4
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
+ 138 more Show less
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
43.0.1
43.0.3
44.0.0
44.0.1
44.0.2
44.0.3
45.0.0
45.0.1
45.0.2
45.0.3
45.0.4
45.0.5
45.0.6
45.0.7
46.0.0
46.0.1
46.0.2
46.0.3
46.0.4
Fixed in
46.0.5
References
Updated Jul 13, 2026 · Source: OSV.dev
GHSA-h4gh-qq45-vh27
Sep 03, 2024
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Medium
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 37.0.0-43.0.0 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20240903.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
+ 22 more Show less
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
42.0.4
42.0.5
42.0.6
42.0.7
42.0.8
43.0.0
Fixed in
43.0.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-26130
GHSA-6vqw-3v5j-54x4
PYSEC-2024-225
Feb 21, 2024
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
If
Then a NULL pointer dereference would occur, crashing the Python process. This has been resolved, and now a Patched in https://github.com/pyca/cryptography/pull/10423 Affected versions
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
+ 11 more Show less
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
41.0.6
41.0.7
42.0.0
42.0.1
42.0.2
42.0.3
Fixed in
42.0.4
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2023-49083
PYSEC-2023-254
GHSA-jfhm-5ghh-2f97
Nov 29, 2023
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling Affected versions
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
+ 30 more Show less
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
41.0.4
41.0.5
Fixed in
41.0.6
References
Updated Feb 17, 2024 · Source: OSV.dev
GHSA-v8gr-m533-ghj9
Sep 21, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 2.5-41.0.3 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230908.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
+ 37 more Show less
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
41.0.3
Fixed in
41.0.4
References Updated Feb 04, 2026 · Source: OSV.dev
GHSA-jm77-qphf-c4w8
Aug 01, 2023
pyca/cryptography's wheels include vulnerable OpenSSL
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.8-41.0.2 are vulnerable to several security issues. More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20230731.txt, https://www.openssl.org/news/secadv/20230719.txt, and https://www.openssl.org/news/secadv/20230714.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.8
0.8.1
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
+ 88 more Show less
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
41.0.0
41.0.1
41.0.2
Fixed in
41.0.3
References
Updated Feb 04, 2026 · Source: OSV.dev
GHSA-5cpq-8wj7-hf2v
Jun 02, 2023
Vulnerable OpenSSL included in cryptography wheels
Low
pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography 0.5-40.0.2 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://www.openssl.org/news/secadv/20230530.txt. If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions. Affected versions
0.5
0.5.1
0.5.2
0.5.3
0.5.4
0.6
0.6.1
0.7
0.7.1
0.7.2
0.8
0.8.1
+ 95 more Show less
0.8.2
0.9
0.9.1
0.9.2
0.9.3
1.0
1.0.1
1.0.2
1.1
1.1.1
1.1.2
1.2
1.2.1
1.2.2
1.2.3
1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.4
1.5
1.5.1
1.5.2
1.5.3
1.6
1.7
1.7.1
1.7.2
1.8
1.8.1
1.8.2
1.9
2.0
2.0.1
2.0.2
2.0.3
2.1
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.2.1
2.2.2
2.3
2.3.1
2.4
2.4.1
2.4.2
2.5
2.6
2.6.1
2.7
2.8
2.9
2.9.1
2.9.2
3.0
3.1
3.1.1
3.2
3.2.1
3.3
3.3.1
3.3.2
3.4
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
35.0.0
36.0.0
36.0.1
36.0.2
37.0.0
37.0.1
37.0.2
37.0.3
37.0.4
38.0.0
38.0.1
38.0.2
38.0.3
38.0.4
39.0.0
39.0.1
39.0.2
40.0.0
40.0.1
40.0.2
Fixed in
41.0.0
References Updated Feb 04, 2026 · Source: OSV.dev |