Security: pyca/cryptography
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timingGHSA-g6cj-pr64-35w5 published
Jul 31, 2026 by alexModerate -
Vulnerable OpenSSL included in cryptography wheelsGHSA-537c-gmf6-5ccf published
Jun 9, 2026 by alexModerate -
Duplicate self-signed intermediates can cause exponential path-buildingGHSA-jwv3-5hgf-82ww published
Jul 31, 2026 by alexLow -
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtreesGHSA-m2h6-j472-rp4c published
Jul 31, 2026 by alexLow -
Buffer overflow if non-contiguous buffers were passed to APIsGHSA-p423-j2cm-9vmq published
Apr 8, 2026 by alexModerate -
X.509: bypass of name constraints on wildcard SANs with matching peer namesGHSA-m959-cc7f-wv43 published
Mar 25, 2026 by alexLow -
Subgroup Attack Due to Missing Subgroup Validation for SECT CurvesGHSA-r6ph-v2qm-q3c2 published
Feb 10, 2026 by alexHigh -
Vulnerable OpenSSL included in cryptography wheelsGHSA-79v4-65xg-pq4g published
Feb 11, 2025 by alexLow -
Vulnerable OpenSSL included in cryptography wheelsGHSA-h4gh-qq45-vh27 published
Sep 3, 2024 by alexModerate -
NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash overrideGHSA-6vqw-3v5j-54x4 published
Feb 21, 2024 by alexModerate
Learn more about advisories related to pyca/cryptography in the GitHub Advisory Database