Skip to content
COOEY

EXPOSURES › CVE-2026-39892

CVE-2026-39892

CRITICAL
DETAIL
SourceNVD · cve Published2026-04-08 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-39892 ↗
SHAME 35/100

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulner

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.