Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-39892

Опубликовано: 08 апр. 2026
Источник: nvd
CVSS3: 9.8
CVSS3: 7.3
EPSS Низкий

Описание

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*
Версия от 45.0.0 (включая) до 46.0.7 (исключая)

EPSS

Процентиль: 48%
0.00652
Низкий

9.8 Critical

CVSS3

7.3 High

CVSS3

Дефекты

CWE-119
CWE-131

Связанные уязвимости

CVSS3: 9.8
ubuntu
4 месяца назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

CVSS3: 7.3
redhat
4 месяца назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

CVSS3: 9.8
debian
4 месяца назад

cryptography is a package designed to expose cryptographic primitives ...

github
4 месяца назад

Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs

EPSS

Процентиль: 48%
0.00652
Низкий

9.8 Critical

CVSS3

7.3 High

CVSS3

Дефекты

CWE-119
CWE-131