pypi

cryptography

View on pypi registry
31 Total advisories
31 Vulnerabilities
0 Malware

Dependency scanning

Check whether cryptography is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
PyPI

GHSA-537c-gmf6-5ccf

Vulnerable OpenSSL included in cryptography wheels

HIGH 7.5
PyPI

CVE-2024-26130

CVE-2024-26130

HIGH 7.5
PyPI

CVE-2024-26130

cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override

UNKNOWN
PyPI

CVE-2023-38325

CVE-2023-38325

UNKNOWN
PyPI

CVE-2026-39892

Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs

MEDIUM 5.3
PyPI

CVE-2026-34073

cryptography has incomplete DNS name constraint enforcement on peer names

CRITICAL 9.8
PyPI

CVE-2026-39892

CVE-2026-39892

MEDIUM 5.3
PyPI

CVE-2026-34073

CVE-2026-34073

MEDIUM 5.5
PyPI

CVE-2024-0727

Null pointer dereference in PKCS12 parsing

UNKNOWN
PyPI

CVE-2026-26007

cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves

MEDIUM 6.5
PyPI

CVE-2023-23931

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

HIGH 7.5
PyPI

CVE-2023-50782

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

UNKNOWN
PyPI

CVE-2023-23931

CVE-2023-23931

UNKNOWN
PyPI

GHSA-v8gr-m533-ghj9

Vulnerable OpenSSL included in cryptography wheels

UNKNOWN
PyPI

GHSA-jm77-qphf-c4w8

pyca/cryptography's wheels include vulnerable OpenSSL

MEDIUM 5.9
PyPI

CVE-2023-49083

cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

HIGH 7.4
PyPI

CVE-2023-0286

Vulnerable OpenSSL included in cryptography wheels

HIGH 7.5
PyPI

CVE-2023-38325

cryptography mishandles SSH certificates

UNKNOWN
PyPI

CVE-2024-12797

Vulnerable OpenSSL included in cryptography wheels

UNKNOWN
PyPI

GHSA-h4gh-qq45-vh27

pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels

UNKNOWN
PyPI

GHSA-5cpq-8wj7-hf2v

Vulnerable OpenSSL included in cryptography wheels

CRITICAL 9.1
PyPI

CVE-2020-36242

PyCA Cryptography symmetrically encrypting large values can lead to integer overflow

UNKNOWN
PyPI

GHSA-39hc-v87j-747x

Vulnerable OpenSSL included in cryptography wheels

MEDIUM 5.9
PyPI

CVE-2020-25659

RSA decryption vulnerable to Bleichenbacher timing vulnerability

HIGH 7.5
PyPI

CVE-2016-9243

Improper input validation in cryptography

HIGH 7.5
PyPI

CVE-2018-10903

PyCA Cryptography vulnerable to GCM tag forgery

HIGH 7.5
PyPI

CVE-2023-49083

CVE-2023-49083

UNKNOWN
PyPI

CVE-2020-36242

CVE-2020-36242

UNKNOWN
PyPI

CVE-2020-25659

CVE-2020-25659

UNKNOWN
PyPI

CVE-2018-10903

CVE-2018-10903

UNKNOWN
PyPI

CVE-2016-9243

CVE-2016-9243

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes