Dependency scanning
Check whether cryptography is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
GHSA-537c-gmf6-5ccf
Vulnerable OpenSSL included in cryptography wheels
CVE-2024-26130
CVE-2024-26130
CVE-2024-26130
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
CVE-2023-38325
CVE-2023-38325
CVE-2026-39892
Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs
CVE-2026-34073
cryptography has incomplete DNS name constraint enforcement on peer names
CVE-2026-39892
CVE-2026-39892
CVE-2026-34073
CVE-2026-34073
CVE-2024-0727
Null pointer dereference in PKCS12 parsing
CVE-2026-26007
cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
CVE-2023-23931
Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
CVE-2023-50782
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
CVE-2023-23931
CVE-2023-23931
GHSA-v8gr-m533-ghj9
Vulnerable OpenSSL included in cryptography wheels
GHSA-jm77-qphf-c4w8
pyca/cryptography's wheels include vulnerable OpenSSL
CVE-2023-49083
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
CVE-2023-0286
Vulnerable OpenSSL included in cryptography wheels
CVE-2023-38325
cryptography mishandles SSH certificates
CVE-2024-12797
Vulnerable OpenSSL included in cryptography wheels
GHSA-h4gh-qq45-vh27
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
GHSA-5cpq-8wj7-hf2v
Vulnerable OpenSSL included in cryptography wheels
CVE-2020-36242
PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
GHSA-39hc-v87j-747x
Vulnerable OpenSSL included in cryptography wheels
CVE-2020-25659
RSA decryption vulnerable to Bleichenbacher timing vulnerability
CVE-2016-9243
Improper input validation in cryptography
CVE-2018-10903
PyCA Cryptography vulnerable to GCM tag forgery
CVE-2023-49083
CVE-2023-49083
CVE-2020-36242
CVE-2020-36242
CVE-2020-25659
CVE-2020-25659
CVE-2018-10903
CVE-2018-10903
CVE-2016-9243
CVE-2016-9243
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes