Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

fstec логотип

BDU:2026-14094

6 месяцев назад

Уязвимость пакета cryptography интерпретатора языка программирования Python, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-34073

6 месяцев назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-34073

6 месяцев назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-34073

6 месяцев назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-34073

6 месяцев назад

cryptography has incomplete DNS name constraint enforcement on peer names

EPSS: Низкий
debian логотип

CVE-2026-34073

6 месяцев назад

cryptography is a package designed to expose cryptographic primitives ...

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260728-80-0021

около 2 месяцев назад

Уязвимость python-cryptography

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-m959-cc7f-wv43

6 месяцев назад

cryptography has incomplete DNS name constraint enforcement on peer names

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20506-1

5 месяцев назад

Security update for python-cryptography

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-14094

Уязвимость пакета cryptography интерпретатора языка программирования Python, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.3
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-34073

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-34073

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

CVSS3: 3.7
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-34073

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2026-34073

cryptography has incomplete DNS name constraint enforcement on peer names

0%
Низкий
6 месяцев назад
debian логотип
CVE-2026-34073

cryptography is a package designed to expose cryptographic primitives ...

CVSS3: 5.3
0%
Низкий
6 месяцев назад
redos логотип
ROS-20260728-80-0021

Уязвимость python-cryptography

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-m959-cc7f-wv43

cryptography has incomplete DNS name constraint enforcement on peer names

CVSS3: 5.3
0%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20506-1

Security update for python-cryptography

5 месяцев назад

Уязвимостей на страницу