CVE-2026-39892
Critical · CVSS 9.8pyca/cryptography — Buffer overflow via non-contiguous buffer in Python buffer API
- CVSS
- 9.8
- nvd
- EPSS
- 0.65%
- 48th pct
- KEV
- No
- Class
- oss containerizable
- CWE-119, CWE-131
Description
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
Search profile — drives PoC discovery
Symbols Hash.update()non-contiguous bufferPyBUF_CONTIGPy_bufferPyObject_GetBufferCWE-119CWE-131
Keywords CVE-2026-39892GHSA-p423-j2cm-9vmqcryptography buffer overflowpyca cryptography non-contiguous buffercryptography 46.0.7cryptography Hash.update buffer overflowpython cryptography buffer overflow poc
Versions: >=45.0.0, <46.0.7
Affected packages
| PyPI | cryptography | 45.0.0 → 46.0.7 |
References
- https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq
- http://www.openwall.com/lists/oss-security/2026/04/08/12
- https://access.redhat.com/errata/RHSA-2026:19375
- https://access.redhat.com/errata/RHSA-2026:20338
- https://access.redhat.com/errata/RHSA-2026:21017
- https://access.redhat.com/errata/RHSA-2026:22465
- https://access.redhat.com/errata/RHSA-2026:22629
- https://access.redhat.com/errata/RHSA-2026:22840
- https://access.redhat.com/errata/RHSA-2026:23361
- https://access.redhat.com/errata/RHSA-2026:24483
- https://access.redhat.com/errata/RHSA-2026:24761
- https://access.redhat.com/errata/RHSA-2026:24762
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z