EXPOSURES › CVE-2026-39892
CVE-2026-39892
CRITICAL
DETAIL
SourceNVD · cve
Published2026-04-08
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-39892 ↗
SHAME 35/100
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulner
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.