← Vulnerability feed

Vulnerability record · CVE-2026-39892 · published 8 April 2026

CVE-2026-39892: Cryptography.io cryptography memory buffer overflow vulnerability

CCryptography.Io · Cryptography

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

6.9 CVSS 4.0 Medium EPSS 0.76% · top 46.6% CWE-119 · Memory buffer overflowCWE-131 · CWE-131
6.9CVSS 4.0 base score
0.76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References
10 Sep 2026Last modified by NVD

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/04/08/12 Mailing ListRelease NotesThird Party Advisory
https://access.redhat.com/errata/RHSA-2026:19375
https://access.redhat.com/errata/RHSA-2026:20338
https://access.redhat.com/errata/RHSA-2026:21017
https://access.redhat.com/errata/RHSA-2026:22465
https://access.redhat.com/errata/RHSA-2026:22629
https://access.redhat.com/errata/RHSA-2026:22840
https://access.redhat.com/errata/RHSA-2026:23361
https://access.redhat.com/errata/RHSA-2026:24483
https://access.redhat.com/errata/RHSA-2026:24761
https://access.redhat.com/errata/RHSA-2026:24762
https://access.redhat.com/errata/RHSA-2026:24853
https://access.redhat.com/errata/RHSA-2026:24866
https://access.redhat.com/errata/RHSA-2026:24977
https://access.redhat.com/errata/RHSA-2026:30088
https://access.redhat.com/errata/RHSA-2026:30089
https://access.redhat.com/errata/RHSA-2026:37275
https://access.redhat.com/errata/RHSA-2026:42644
https://access.redhat.com/errata/RHSA-2026:43651
https://access.redhat.com/errata/RHSA-2026:43670
https://access.redhat.com/errata/RHSA-2026:43851
https://access.redhat.com/errata/RHSA-2026:43853
https://access.redhat.com/errata/RHSA-2026:43854
https://access.redhat.com/errata/RHSA-2026:43855
https://access.redhat.com/errata/RHSA-2026:46956
https://access.redhat.com/errata/RHSA-2026:7295
https://access.redhat.com/security/cve/CVE-2026-39892
https://bugzilla.redhat.com/show_bug.cgi?id=2456735
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39892.json

Track CVE-2026-39892 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2020-36242Cryptography.io cryptography integer overflow vulnerabilityIn the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an in…EPSS 6.7%8.2CVE-2026-26007Cryptography.io cryptography insufficient verification of data authenticity vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers …EPSS 0.34%7.5CVE-2024-26130Cryptography.io cryptography null pointer dereference vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to versi…EPSS 0.83%7.5CVE-2023-50782Redhat ansible automation platform observable discrepancy vulnerabilityA flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA …EPSS 1.1%7.5CVE-2023-49083Cryptography.io cryptography null pointer dereference vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `loa…EPSS 0.99%7.5CVE-2023-38325Cryptography.io cryptography improper certificate validation vulnerabilityThe cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.EPSS 0.73%7.5CVE-2016-9243Cryptography.io cryptography vulnerabilityHKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.EPSS 3.5%6.5CVE-2023-23931Cryptography.io cryptography vulnerabilitycryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` wou…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-39892), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.