cryptography.io records
11 published records for vendor cryptography.io.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference2
- CWE-295 Improper Certificate Validation2
- CWE-203 Observable Discrepancy1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-385 Covert Timing Channel1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2020-36242No exploit | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could resultcryptography.io · cryptography · CWE-190 | Critical9.1 | — | 6.7% | Feb 7, 2021 |
32Monitor | CVE-2026-26007No exploit | cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curvescryptography.io · cryptography · CWE-345 | High8.2 | — | 0.3% | Feb 10, 2026 |
31Monitor | CVE-2016-9243No exploit | HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.cryptography.io · cryptography | High7.5 | — | 3.5% | Mar 27, 2017 |
30Monitor | CVE-2023-50782No exploit | Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659redhat · ansible automation platform · CWE-203 | High7.5 | — | 1.1% | Feb 5, 2024 |
30Monitor | CVE-2023-49083No exploit | cryptography vulnerable to NULL-dereference when loading PKCS7 certificatescryptography.io · cryptography · CWE-476 | High7.5 | — | 1.0% | Nov 29, 2023 |
30Monitor | CVE-2024-26130No exploit | cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash overcryptography.io · cryptography · CWE-476 | High7.5 | — | 0.8% | Feb 21, 2024 |
30Monitor | CVE-2023-38325No exploit | The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.cryptography.io · cryptography · CWE-295 | High7.5 | — | 0.7% | Jul 14, 2023 |
27Monitor | CVE-2026-39892No exploit | cryptography has a buffer overflow if non-contiguous buffers were passed to APIscryptography.io · cryptography · CWE-119 | Medium6.9 | — | 0.8% | Apr 8, 2026 |
26Monitor | CVE-2023-23931No exploit | Cipher.update_into can corrupt memory in pyca cryptographycryptography.io · cryptography · CWE-754 | Medium6.5 | — | 1.3% | Feb 7, 2023 |
24Monitor | CVE-2020-25659No exploit | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 cryptography.io · cryptography · CWE-385 | Medium5.9 | — | 2.4% | Jan 11, 2021 |
6Monitor | CVE-2026-34073No exploit | cryptography has incomplete DNS name constraint enforcement on peer namescryptography.io · cryptography · CWE-295 | Low1.7 | — | 0.2% | Mar 30, 2026 |
- CVE-2020-3624238Monitor
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result
CriticalCVSS 9.1No exploitEPSS 7%cryptography.io · cryptographyFeb 7, 2021
- CVE-2026-2600732Monitor
cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
HighCVSS 8.2No exploitEPSS 0%cryptography.io · cryptographyFeb 10, 2026
- CVE-2016-924331Monitor
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
HighCVSS 7.5No exploitEPSS 3%cryptography.io · cryptographyMar 27, 2017
- CVE-2023-5078230Monitor
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
HighCVSS 7.5No exploitEPSS 1%redhat · ansible automation platformFeb 5, 2024
- CVE-2023-4908330Monitor
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
HighCVSS 7.5No exploitEPSS 1%cryptography.io · cryptographyNov 29, 2023
- CVE-2024-2613030Monitor
cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash over
HighCVSS 7.5No exploitEPSS 1%cryptography.io · cryptographyFeb 21, 2024
- CVE-2023-3832530Monitor
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
HighCVSS 7.5No exploitEPSS 1%cryptography.io · cryptographyJul 14, 2023
- CVE-2026-3989227Monitor
cryptography has a buffer overflow if non-contiguous buffers were passed to APIs
MediumCVSS 6.9No exploitEPSS 1%cryptography.io · cryptographyApr 8, 2026
- CVE-2023-2393126Monitor
Cipher.update_into can corrupt memory in pyca cryptography
MediumCVSS 6.5No exploitEPSS 1%cryptography.io · cryptographyFeb 7, 2023
- CVE-2020-2565924Monitor
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5
MediumCVSS 5.9No exploitEPSS 2%cryptography.io · cryptographyJan 11, 2021
- CVE-2026-340736Monitor
cryptography has incomplete DNS name constraint enforcement on peer names
LowCVSS 1.7No exploitEPSS 0%cryptography.io · cryptographyMar 30, 2026