Cryptography.io
cryptography.io
11 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (11)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cryptography.io 1Cryptography Apr 15, 2026 Apr 8, 2026 6.9 MEDIUM· v4 9.8 CRITICAL· v3 N/A· v2 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash...Show more |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not th...Show more |
1Cryptography.io 1Cryptography Feb 23, 2026 Feb 10, 2026 8.2 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumber...Show more |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with bo...Show more |
3Couchbase Cryptography.ioRedhat5Ansible Automation Platform Couchbase ServerCryptography+2 moreMar 24, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and...Show more |
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. |
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provi...Show more |
3Cryptography.io FedoraprojectOracle3Communications Cloud Native Core Network Function Cloud Native Environment CryptographyFedoraNov 21, 2024 Feb 7, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class...Show more |
2Cryptography.io Oracle2Communications Cloud Native Core Network Function Cloud Native Environment CryptographyNov 21, 2024 Jan 11, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext. |
3Canonical Cryptography.ioFedoraproject3Cryptography FedoraUbuntu LinuxMay 13, 2026 Mar 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size. |