Home/Product/cryptography.io cryptography
Product

cryptography.io cryptography

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-39892
>= 45.0.0 and < 46.0.7
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0
9.8CRITICAL
CVE-2026-34073
< 46.0.6
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, D
5.3MEDIUM
CVE-2026-26007
< 46.0.5
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the publi
6.5MEDIUM
CVE-2024-26130
>= 38.0.0 and < 42.0.4
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0
7.5HIGH
CVE-2023-50782
< 42.0.0
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS se
7.5HIGH
CVE-2023-49083
>= 3.1 and < 41.0.6
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_ce
5.9MEDIUM
CVE-2023-38325
>= 40.0.0 and < 41.0.2
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
7.5HIGH
CVE-2023-23931
>= 1.8 and < 39.0.1
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Ciph
4.8MEDIUM
CVE-2020-36242
< 3.3.2
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values co
9.1CRITICAL
CVE-2020-25659
all versions
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PK
5.9MEDIUM
CVE-2018-10903
>= 1.9.0 and < 2.3
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag
7.5HIGH
CVE-2016-9243
<= 1.5.2
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin