← Vulnerability feed

Vulnerability record · CVE-2023-38325 · published 14 July 2023

CVE-2023-38325: Cryptography.io cryptography improper certificate validation vulnerability

CCryptography.Io · Cryptography

The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

7.5 CVSS 3.1 High EPSS 0.73% · top 47.5% CWE-295 · Improper certificate validation
7.5CVSS 3.1 base score
0.73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-38325 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2020-36242Cryptography.io cryptography integer overflow vulnerabilityIn the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an in…EPSS 6.7%8.2CVE-2026-26007Cryptography.io cryptography insufficient verification of data authenticity vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers …EPSS 0.34%7.5CVE-2024-26130Cryptography.io cryptography null pointer dereference vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to versi…EPSS 0.83%7.5CVE-2023-50782Redhat ansible automation platform observable discrepancy vulnerabilityA flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA …EPSS 1.1%7.5CVE-2023-49083Cryptography.io cryptography null pointer dereference vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `loa…EPSS 0.99%7.5CVE-2016-9243Cryptography.io cryptography vulnerabilityHKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.EPSS 3.5%6.9CVE-2026-39892Cryptography.io cryptography memory buffer overflow vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contig…EPSS 0.76%6.5CVE-2023-23931Cryptography.io cryptography vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` wou…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2023-38325), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.