{"schema_version":1,"title":"cryptography (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in cryptography (PyPI): 0 in the last 7 days and 5 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-69248, was published on 3 August 2026.","url":"https://junglewise.ai/threats/technologies/cryptography","json_url":"https://junglewise.ai/threats/technologies/cryptography.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/cryptography","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":20,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":9},"latest":[{"cve":"CVE-2026-69248","cvss":4,"epss":0.0031,"slug":"cve-2026-69248-pyca-cryptography-improper-certificate-validation-in-name","title":"pyca cryptography improper certificate validation in Name Constraints","severity":"medium","exploited":false,"published_at":"2026-08-03T21:26:57+00:00","url":"https://junglewise.ai/threats/cve-2026-69248-pyca-cryptography-improper-certificate-validation-in-name"},{"cve":"CVE-2026-69249","cvss":4,"epss":0.0033,"slug":"cve-2026-69249-pyca-cryptography-exponential-path-building-in-x-509-verification","title":"Pyca Cryptography exponential path-building in X.509 verification","severity":"high","exploited":false,"published_at":"2026-08-03T21:26:50+00:00","url":"https://junglewise.ai/threats/cve-2026-69249-pyca-cryptography-exponential-path-building-in-x-509-verification"},{"cve":"CVE-2026-69247","cvss":4,"epss":0.0027,"slug":"cve-2026-69247-pyca-cryptography-bleichenbacher-oracle-in-pkcs-7-decryption","title":"pyca cryptography Bleichenbacher oracle in PKCS#7 decryption","severity":"high","exploited":false,"published_at":"2026-08-03T21:17:00+00:00","url":"https://junglewise.ai/threats/cve-2026-69247-pyca-cryptography-bleichenbacher-oracle-in-pkcs-7-decryption"},{"cve":"CVE-2024-12797","epss":0.0253,"slug":"cve-2024-12797-vulnerable-openssl-included-in-cryptography-wheels","title":"PYSEC-2026-1284 - Vulnerable OpenSSL included in cryptography wheels","severity":"info","exploited":false,"published_at":"2026-07-07T14:34:49.574389+00:00","url":"https://junglewise.ai/threats/cve-2024-12797-vulnerable-openssl-included-in-cryptography-wheels"},{"cve":"CVE-2023-50782","cvss":3.1,"epss":0.0112,"slug":"cve-2023-50782-python-cryptography-package-vulnerable-to-bleichenbacher-timing","title":"PYSEC-2026-1283 - Python Cryptography package vulnerable to Bleichenbacher timing oracle attack","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:32.057431+00:00","url":"https://junglewise.ai/threats/cve-2023-50782-python-cryptography-package-vulnerable-to-bleichenbacher-timing"},{"cvss":7.5,"slug":"pyca-cryptography-vulnerable-openssl-in-pre-compiled-wheels-d6089b68","title":"Pyca Cryptography vulnerable OpenSSL in pre-compiled wheels","severity":"high","exploited":false,"published_at":"2026-06-15T20:12:27+00:00","url":"https://junglewise.ai/threats/pyca-cryptography-vulnerable-openssl-in-pre-compiled-wheels-d6089b68"},{"cve":"CVE-2026-39892","cvss":9.8,"epss":0.0076,"slug":"cve-2026-39892-pyca-cryptography-buffer-overflow-in-buffer-accepting-apis","title":"PyCA cryptography buffer overflow in buffer-accepting APIs","severity":"critical","exploited":false,"published_at":"2026-04-08T21:17:01.547+00:00","url":"https://junglewise.ai/threats/cve-2026-39892-pyca-cryptography-buffer-overflow-in-buffer-accepting-apis"},{"cve":"CVE-2026-34073","cvss":5.3,"epss":0.0017,"slug":"cve-2026-34073-pyca-cryptography-incomplete-dns-name-constraint-enforcement","title":"pyca cryptography incomplete DNS name constraint enforcement","severity":"medium","exploited":false,"published_at":"2026-03-27T19:56:21+00:00","url":"https://junglewise.ai/threats/cve-2026-34073-pyca-cryptography-incomplete-dns-name-constraint-enforcement"},{"cve":"CVE-2026-26007","cvss":6.5,"epss":0.0034,"slug":"cve-2026-26007-pyca-cryptography-missing-subgroup-validation-in-sect-curves","title":"PyCA cryptography missing subgroup validation in SECT curves","severity":"medium","exploited":false,"published_at":"2026-02-10T22:17:00.307+00:00","url":"https://junglewise.ai/threats/cve-2026-26007-pyca-cryptography-missing-subgroup-validation-in-sect-curves"},{"cve":"CVE-2024-26130","cvss":3.1,"epss":0.0083,"slug":"cve-2024-26130-cryptography-null-pointer-dereference-with-pkcs12-serialize-key","title":"PYSEC-2024-225 - cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior","severity":"low","exploited":false,"published_at":"2024-02-21T17:15:09+00:00","url":"https://junglewise.ai/threats/cve-2024-26130-cryptography-null-pointer-dereference-with-pkcs12-serialize-key"},{"cve":"CVE-2024-0727","cvss":5.5,"epss":0.0319,"slug":"cve-2024-0727-openssl-null-pointer-dereference-in-pkcs12-decoding","title":"OpenSSL NULL pointer dereference in PKCS12 decoding","severity":"medium","exploited":false,"published_at":"2024-01-26T09:15:07.637+00:00","url":"https://junglewise.ai/threats/cve-2024-0727-openssl-null-pointer-dereference-in-pkcs12-decoding"},{"cve":"CVE-2023-49083","cvss":3.1,"epss":0.0099,"slug":"cve-2023-49083-cryptography-vulnerable-to-null-dereference-when-loading-pkcs7","title":"PYSEC-2023-254 - cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates","severity":"low","exploited":false,"published_at":"2023-11-29T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-49083-cryptography-vulnerable-to-null-dereference-when-loading-pkcs7"},{"cve":"CVE-2023-38325","cvss":3.1,"epss":0.0073,"slug":"cve-2023-38325-cryptography-mishandles-ssh-certificates","title":"PYSEC-2023-112 - The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.","severity":"low","exploited":false,"published_at":"2023-07-14T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38325-cryptography-mishandles-ssh-certificates"},{"cve":"CVE-2023-23931","cvss":3.1,"epss":0.013,"slug":"cve-2023-23931-cipher-update-into-can-corrupt-memory-if-passed-an-immutable","title":"PYSEC-2023-11 - cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_","severity":"low","exploited":false,"published_at":"2023-02-07T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-23931-cipher-update-into-can-corrupt-memory-if-passed-an-immutable"},{"cve":"CVE-2023-0286","cvss":3.1,"epss":0.595,"slug":"cve-2023-0286-vulnerable-openssl-included-in-cryptography-wheels","title":"RUSTSEC-2023-0006 - X.400 address type confusion in X.509 `GeneralName`","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0286-vulnerable-openssl-included-in-cryptography-wheels"},{"slug":"pyca-cryptography-vulnerable-openssl-in-wheels-1b0dbb8c","title":"pyca cryptography vulnerable OpenSSL in wheels","severity":"info","exploited":false,"published_at":"2022-11-02T18:11:56+00:00","url":"https://junglewise.ai/threats/pyca-cryptography-vulnerable-openssl-in-wheels-1b0dbb8c"},{"cve":"CVE-2020-36242","cvss":3.1,"epss":0.0672,"slug":"cve-2020-36242-pyca-cryptography-symmetrically-encrypting-large-values-can-lead","title":"PYSEC-2021-63 - In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result","severity":"low","exploited":false,"published_at":"2021-02-07T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-36242-pyca-cryptography-symmetrically-encrypting-large-values-can-lead"},{"cve":"CVE-2020-25659","cvss":3.1,"epss":0.0243,"slug":"cve-2020-25659-rsa-decryption-vulnerable-to-bleichenbacher-timing-vulnerability","title":"PYSEC-2021-62 - python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5","severity":"low","exploited":false,"published_at":"2021-01-11T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-25659-rsa-decryption-vulnerable-to-bleichenbacher-timing-vulnerability"},{"cve":"CVE-2018-10903","cvss":3,"epss":0.032,"slug":"cve-2018-10903-pyca-cryptography-vulnerable-to-gcm-tag-forgery","title":"PYSEC-2018-52 - A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. I","severity":"low","exploited":false,"published_at":"2018-07-30T16:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-10903-pyca-cryptography-vulnerable-to-gcm-tag-forgery"},{"cve":"CVE-2016-9243","cvss":3,"epss":0.0346,"slug":"cve-2016-9243-improper-input-validation-in-cryptography","title":"PYSEC-2017-8 - HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.","severity":"low","exploited":false,"published_at":"2017-03-27T17:59:00+00:00","url":"https://junglewise.ai/threats/cve-2016-9243-improper-input-validation-in-cryptography"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"cryptography (PyPI)","slug":"cryptography","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://cryptography.io/","repo_url":"https://github.com/pyca/cryptography","description":"A Python library that provides cryptographic recipes and primitives to Python developers.","url":"https://junglewise.ai/threats/technologies/cryptography"},"most_severe":[{"cve":"CVE-2026-39892","cvss":9.8,"epss":0.0076,"slug":"cve-2026-39892-pyca-cryptography-buffer-overflow-in-buffer-accepting-apis","title":"PyCA cryptography buffer overflow in buffer-accepting APIs","severity":"critical","exploited":false,"published_at":"2026-04-08T21:17:01.547+00:00","url":"https://junglewise.ai/threats/cve-2026-39892-pyca-cryptography-buffer-overflow-in-buffer-accepting-apis"},{"cvss":7.5,"slug":"pyca-cryptography-vulnerable-openssl-in-pre-compiled-wheels-d6089b68","title":"Pyca Cryptography vulnerable OpenSSL in pre-compiled wheels","severity":"high","exploited":false,"published_at":"2026-06-15T20:12:27+00:00","url":"https://junglewise.ai/threats/pyca-cryptography-vulnerable-openssl-in-pre-compiled-wheels-d6089b68"},{"cve":"CVE-2026-69249","cvss":4,"epss":0.0033,"slug":"cve-2026-69249-pyca-cryptography-exponential-path-building-in-x-509-verification","title":"Pyca Cryptography exponential path-building in X.509 verification","severity":"high","exploited":false,"published_at":"2026-08-03T21:26:50+00:00","url":"https://junglewise.ai/threats/cve-2026-69249-pyca-cryptography-exponential-path-building-in-x-509-verification"},{"cve":"CVE-2026-69247","cvss":4,"epss":0.0027,"slug":"cve-2026-69247-pyca-cryptography-bleichenbacher-oracle-in-pkcs-7-decryption","title":"pyca cryptography Bleichenbacher oracle in PKCS#7 decryption","severity":"high","exploited":false,"published_at":"2026-08-03T21:17:00+00:00","url":"https://junglewise.ai/threats/cve-2026-69247-pyca-cryptography-bleichenbacher-oracle-in-pkcs-7-decryption"},{"cve":"CVE-2026-26007","cvss":6.5,"epss":0.0034,"slug":"cve-2026-26007-pyca-cryptography-missing-subgroup-validation-in-sect-curves","title":"PyCA cryptography missing subgroup validation in SECT curves","severity":"medium","exploited":false,"published_at":"2026-02-10T22:17:00.307+00:00","url":"https://junglewise.ai/threats/cve-2026-26007-pyca-cryptography-missing-subgroup-validation-in-sect-curves"},{"cve":"CVE-2024-0727","cvss":5.5,"epss":0.0319,"slug":"cve-2024-0727-openssl-null-pointer-dereference-in-pkcs12-decoding","title":"OpenSSL NULL pointer dereference in PKCS12 decoding","severity":"medium","exploited":false,"published_at":"2024-01-26T09:15:07.637+00:00","url":"https://junglewise.ai/threats/cve-2024-0727-openssl-null-pointer-dereference-in-pkcs12-decoding"},{"cve":"CVE-2026-34073","cvss":5.3,"epss":0.0017,"slug":"cve-2026-34073-pyca-cryptography-incomplete-dns-name-constraint-enforcement","title":"pyca cryptography incomplete DNS name constraint enforcement","severity":"medium","exploited":false,"published_at":"2026-03-27T19:56:21+00:00","url":"https://junglewise.ai/threats/cve-2026-34073-pyca-cryptography-incomplete-dns-name-constraint-enforcement"},{"cve":"CVE-2026-69248","cvss":4,"epss":0.0031,"slug":"cve-2026-69248-pyca-cryptography-improper-certificate-validation-in-name","title":"pyca cryptography improper certificate validation in Name Constraints","severity":"medium","exploited":false,"published_at":"2026-08-03T21:26:57+00:00","url":"https://junglewise.ai/threats/cve-2026-69248-pyca-cryptography-improper-certificate-validation-in-name"},{"cve":"CVE-2023-0286","cvss":3.1,"epss":0.595,"slug":"cve-2023-0286-vulnerable-openssl-included-in-cryptography-wheels","title":"RUSTSEC-2023-0006 - X.400 address type confusion in X.509 `GeneralName`","severity":"low","exploited":false,"published_at":"2023-02-07T12:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-0286-vulnerable-openssl-included-in-cryptography-wheels"},{"cve":"CVE-2020-36242","cvss":3.1,"epss":0.0672,"slug":"cve-2020-36242-pyca-cryptography-symmetrically-encrypting-large-values-can-lead","title":"PYSEC-2021-63 - In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result","severity":"low","exploited":false,"published_at":"2021-02-07T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-36242-pyca-cryptography-symmetrically-encrypting-large-values-can-lead"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}