CVE-2024-26130 is a NULL pointer dereference vulnerability affecting the cryptography.io cryptography package, versions 38.0.0 through 42.0.3. It occurs when pkcs12.serialize_key_and_certificates is called with a mismatched public key and private key, alongside a specific encryption algorithm configuration, leading to a Python process crash. Rated 7.5 HIGH on CVSS, this vulnerability has a network attack vector and low attack complexity, resulting in high availability impact (denial of service). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 38.0.0, < 42.0.4CPE matchmatch criteria | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
Feb 21, 2024python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
Feb 21, 2024