Logo
vulnerabilityCVE-2026-39892
Name
CVE-2026-39892
Source
NVD ( link)Debian ( link)
Description
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python-cryptography
Exploitable

Vulnerability Ratings#


6.9
CVSSv4
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
44.0.1
Not Affected
buildroot
master
48.0.0
Not Affected
openwrt
master
48.0.0-r1
Not Affected