Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39892

40
FAUCET Score

CVE-2026-39892 is a buffer overflow vulnerability in the Python cryptography package versions 45.0.0 through 46.0.6. The flaw occurs when non-contiguous buffers are passed to APIs accepting Python buffers, such as the Hash.update() function, potentially allowing memory corruption. This vulnerability has been remediated in version 46.0.7 and later. The vulnerability carries a CVSS score of 9.8 (CRITICAL), reflecting a network-accessible attack vector with low complexity and no authentication requirements. An unauthenticated remote attacker could potentially exploit this issue without user interaction to compromise confidentiality, integrity, and availability of affected systems. The FAUCET Risk Score of 55.0/100 indicates moderate overall risk considering multiple risk factors. There is currently no evidence of active exploitation in the wild, with the vulnerability not appearing on the CISA Known Exploited Vulnerabilities (KEV) list. The Exploit Prediction Scoring System (EPSS) score of 0.00021 suggests minimal probability of near-term exploitation. This vulnerability should nonetheless be treated as priority for patching given its critical severity rating, particularly for systems handling cryptographic operations where buffer overflows could have significant consequences.

Impacted Technologies

VendorProductVersion(s)CPE
>= 45.0.0, < 46.0.7CPE matchmatch criteria
cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.65%
Probability of exploitation in next 30 days
EPSS Percentile
47.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0065 is in the 29th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: cryptographyFixed in: 46.0.7
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-p423-j2cm-9vmqmedium

Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs

Apr 8, 2026

References

access.redhat.com / errata/RHSA-2026:19375
access.redhat.com / errata/RHSA-2026:20338
access.redhat.com / errata/RHSA-2026:21017
access.redhat.com / errata/RHSA-2026:22465
access.redhat.com / errata/RHSA-2026:22629
access.redhat.com / errata/RHSA-2026:22840
access.redhat.com / errata/RHSA-2026:23361
access.redhat.com / errata/RHSA-2026:24483
access.redhat.com / errata/RHSA-2026:24761
access.redhat.com / errata/RHSA-2026:24762
access.redhat.com / errata/RHSA-2026:24853
access.redhat.com / errata/RHSA-2026:24866
access.redhat.com / errata/RHSA-2026:24977
access.redhat.com / errata/RHSA-2026:30088
access.redhat.com / errata/RHSA-2026:30089
access.redhat.com / errata/RHSA-2026:37275
access.redhat.com / errata/RHSA-2026:42644
access.redhat.com / errata/RHSA-2026:43651
access.redhat.com / errata/RHSA-2026:43670
access.redhat.com / errata/RHSA-2026:43851
access.redhat.com / errata/RHSA-2026:43853
access.redhat.com / errata/RHSA-2026:43854
access.redhat.com / errata/RHSA-2026:43855
access.redhat.com / errata/RHSA-2026:7295
access.redhat.com / security/cve/CVE-2026-39892
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-39892.json
openwall.com / lists/oss-security/2026/04/08/12
Mailing ListRelease NotesThird Party Advisory
github.com / pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq
Vendor Advisory