← Vulnerability feed

Vulnerability record · CVE-2024-26130 · published 21 February 2024

CVE-2024-26130: Cryptography.io cryptography null pointer dereference vulnerability

CCryptography.Io · Cryptography

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.

7.5 CVSS 3.1 High EPSS 0.83% · top 44.1% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score
0.83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-26130 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2020-36242Cryptography.io cryptography integer overflow vulnerabilityIn the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an in…EPSS 6.7%8.2CVE-2026-26007Cryptography.io cryptography insufficient verification of data authenticity vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers …EPSS 0.34%7.5CVE-2023-50782Redhat ansible automation platform observable discrepancy vulnerabilityA flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA …EPSS 1.1%7.5CVE-2023-49083Cryptography.io cryptography null pointer dereference vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `loa…EPSS 0.99%7.5CVE-2023-38325Cryptography.io cryptography improper certificate validation vulnerabilityThe cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.EPSS 0.73%7.5CVE-2016-9243Cryptography.io cryptography vulnerabilityHKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.EPSS 3.5%6.9CVE-2026-39892Cryptography.io cryptography memory buffer overflow vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contig…EPSS 0.76%6.5CVE-2023-23931Cryptography.io cryptography vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` wou…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2024-26130), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.