← Vulnerability feed

Vulnerability record · CVE-2023-23931 · published 7 February 2023

CVE-2023-23931: Cryptography.io cryptography vulnerability

CCryptography.Io · Cryptography

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

6.5 CVSS 3.1 Medium EPSS 1.3% · top 30.7% CWE-754 · CWE-754
6.5CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-23931 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2020-36242Cryptography.io cryptography integer overflow vulnerabilityIn the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an in…EPSS 6.7%8.2CVE-2026-26007Cryptography.io cryptography insufficient verification of data authenticity vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers …EPSS 0.34%7.5CVE-2024-26130Cryptography.io cryptography null pointer dereference vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to versi…EPSS 0.83%7.5CVE-2023-50782Redhat ansible automation platform observable discrepancy vulnerabilityA flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA …EPSS 1.1%7.5CVE-2023-49083Cryptography.io cryptography null pointer dereference vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `loa…EPSS 0.99%7.5CVE-2023-38325Cryptography.io cryptography improper certificate validation vulnerabilityThe cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.EPSS 0.73%7.5CVE-2016-9243Cryptography.io cryptography vulnerabilityHKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.EPSS 3.5%6.9CVE-2026-39892Cryptography.io cryptography memory buffer overflow vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contig…EPSS 0.76%

Source: NIST National Vulnerability Database (record CVE-2023-23931), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.