Beveiligingsadvies

CVE-2026-39892

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-08 20:49:41
Laatst bijgewerkt 2026-09-07 12:04:56
Toegewezen door GitHub_M
CVSS-score 7.3
Status PUBLISHED

Beschrijving

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.