CVE-2026-34073 is a low-severity vulnerability (CVSS 1.7) affecting the 'cryptography' Python package, specifically versions prior to 46.0.6. This flaw allowed for the bypass of DNS name constraints, enabling a peer to validate against a wildcard certificate even when an excluded subtree constraint was present in a parent certificate. The vulnerability has a network attack vector and high attack complexity, resulting in a low integrity impact. There is no evidence of active exploitation, and no public exploit code is currently available, though it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 46.0.6CPE matchmatch criteria | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.