Back to CVE List

CVE-2026-39892

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-119
Source
NVD
Vendor
pyca
Product
cryptography

External References

Discussion (0)

Add Comment

No comments yet. Be the first!