CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-39892

Critical · CVSS 9.8

pyca/cryptography — Buffer overflow via non-contiguous buffer in Python buffer API

CVSS
9.8
nvd
EPSS
0.65%
48th pct
KEV
No
Class
oss containerizable
CWE-119, CWE-131

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

Search profile — drives PoC discovery

Symbols Hash.update()non-contiguous bufferPyBUF_CONTIGPy_bufferPyObject_GetBufferCWE-119CWE-131
Keywords CVE-2026-39892GHSA-p423-j2cm-9vmqcryptography buffer overflowpyca cryptography non-contiguous buffercryptography 46.0.7cryptography Hash.update buffer overflowpython cryptography buffer overflow poc
Versions: >=45.0.0, <46.0.7

Affected packages

PyPI cryptography 45.0.0 → 46.0.7

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z