Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-14094

Опубликовано: 31 мар. 2026
Источник: fstec
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Уязвимость пакета cryptography интерпретатора языка программирования Python связана с ошибками процедуры подтверждения подлинности сертификата. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, оказать воздействие на целостность защищаемой информации

Вендор

Red Hat, Inc.
ООО «Ред Софт»
Python Cryptographic Authority

Наименование ПО

Red Hat Enterprise Linux
Red Hat Quay
Red Hat Satellite
OpenShift AI
Red Hat OpenShift Lightspeed
Red Hat Trusted Artifact Signer
Red Hat AI Inference Server
Red Hat Discovery
РЕД ОС
Red Hat Enterprise Linux AI
Red Hat Ansible Automation Platform Ansible Core
Ansible Automation Platform
Lightspeed Core
Pen Drive Powered by Red Hat Lightspeed
Red Hat Hardened Images
cryptography

Версия ПО

8 (Red Hat Enterprise Linux)
3 (Red Hat Quay)
6 (Red Hat Satellite)
9 (Red Hat Enterprise Linux)
- (OpenShift AI)
- (Red Hat OpenShift Lightspeed)
- (Red Hat Trusted Artifact Signer)
- (Red Hat AI Inference Server)
2 (Red Hat Discovery)
8.0 (РЕД ОС)
3 (Red Hat Enterprise Linux AI)
2 (Red Hat Ansible Automation Platform Ansible Core)
2 (Ansible Automation Platform)
- (Lightspeed Core)
- (Pen Drive Powered by Red Hat Lightspeed)
- (Red Hat Hardened Images)
до 46.0.6 (cryptography)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО для разработки ИИ

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,3)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/pyca/cryptography/security/advisories/GHSA-m959-cc7f-wv43
Для Ред ОС:
https://redos.red-soft.ru/search/?q=CVE-2026-34073
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-34073

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 5%
0.00154
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
6 месяцев назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

CVSS3: 3.7
redhat
6 месяцев назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

CVSS3: 5.3
nvd
6 месяцев назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

msrc
6 месяцев назад

cryptography has incomplete DNS name constraint enforcement on peer names

CVSS3: 5.3
debian
6 месяцев назад

cryptography is a package designed to expose cryptographic primitives ...

EPSS

Процентиль: 5%
0.00154
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2