Technology · PyPI
cryptography (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in cryptography (PyPI): 0 in the last 7 days and 5 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-69248, was published on 3 August 2026.
- Last 7 days
- 0
- Last 90 days
- 5
- Critical, all time
- 1
- Exploited in the wild
- 0
About cryptography (PyPI)
A Python library that provides cryptographic recipes and primitives to Python developers.
Latest cryptography (PyPI) vulnerabilities
- CVE-2026-69248: pyca cryptography improper certificate validation in Name ConstraintsmediumCVSS 4EPSS 0.3%
- CVE-2026-69249: Pyca Cryptography exponential path-building in X.509 verificationhighCVSS 4EPSS 0.3%
- CVE-2026-69247: pyca cryptography Bleichenbacher oracle in PKCS#7 decryptionhighCVSS 4EPSS 0.3%
- CVE-2024-12797: PYSEC-2026-1284 - Vulnerable OpenSSL included in cryptography wheelsinfoEPSS 2.5%
- CVE-2023-50782: PYSEC-2026-1283 - Python Cryptography package vulnerable to Bleichenbacher timing oracle attacklowCVSS 3.1EPSS 1.1%
- Pyca Cryptography vulnerable OpenSSL in pre-compiled wheelshighCVSS 7.5
- CVE-2026-39892: PyCA cryptography buffer overflow in buffer-accepting APIscriticalCVSS 9.8EPSS 0.8%
- CVE-2026-34073: pyca cryptography incomplete DNS name constraint enforcementmediumCVSS 5.3EPSS 0.2%
- CVE-2026-26007: PyCA cryptography missing subgroup validation in SECT curvesmediumCVSS 6.5EPSS 0.3%
- CVE-2024-26130: PYSEC-2024-225 - cryptography is a package designed to expose cryptographic primitives and recipes to Python developers…lowCVSS 3.1EPSS 0.8%
- CVE-2024-0727: OpenSSL NULL pointer dereference in PKCS12 decodingmediumCVSS 5.5EPSS 3.2%
- CVE-2023-49083: PYSEC-2023-254 - cryptography is a package designed to expose cryptographic primitives and recipes to Python developers…lowCVSS 3.1EPSS 1.0%
- CVE-2023-38325: PYSEC-2023-112 - The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.lowCVSS 3.1EPSS 0.7%
- CVE-2023-23931: PYSEC-2023-11 - cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In…lowCVSS 3.1EPSS 1.3%
- CVE-2023-0286: RUSTSEC-2023-0006 - X.400 address type confusion in X.509 `GeneralName`lowCVSS 3.1EPSS 59.5%
- pyca cryptography vulnerable OpenSSL in wheelsinfo
- CVE-2020-36242: PYSEC-2021-63 - In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically…lowCVSS 3.1EPSS 6.7%
- CVE-2020-25659: PYSEC-2021-62 - python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via…lowCVSS 3.1EPSS 2.4%
- CVE-2018-10903: PYSEC-2018-52 - A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did…lowCVSS 3EPSS 3.2%
- CVE-2016-9243: PYSEC-2017-8 - HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than…lowCVSS 3EPSS 3.5%
Most severe cryptography (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-39892: PyCA cryptography buffer overflow in buffer-accepting APIscriticalCVSS 9.8EPSS 0.8%
- Pyca Cryptography vulnerable OpenSSL in pre-compiled wheelshighCVSS 7.5
- CVE-2026-69249: Pyca Cryptography exponential path-building in X.509 verificationhighCVSS 4EPSS 0.3%
- CVE-2026-69247: pyca cryptography Bleichenbacher oracle in PKCS#7 decryptionhighCVSS 4EPSS 0.3%
- CVE-2026-26007: PyCA cryptography missing subgroup validation in SECT curvesmediumCVSS 6.5EPSS 0.3%
- CVE-2024-0727: OpenSSL NULL pointer dereference in PKCS12 decodingmediumCVSS 5.5EPSS 3.2%
- CVE-2026-34073: pyca cryptography incomplete DNS name constraint enforcementmediumCVSS 5.3EPSS 0.2%
- CVE-2026-69248: pyca cryptography improper certificate validation in Name ConstraintsmediumCVSS 4EPSS 0.3%
- CVE-2023-0286: RUSTSEC-2023-0006 - X.400 address type confusion in X.509 `GeneralName`lowCVSS 3.1EPSS 59.5%
- CVE-2020-36242: PYSEC-2021-63 - In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically…lowCVSS 3.1EPSS 6.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 3 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/cryptography.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "cryptography (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/cryptography, 28 September 2026.