CVE-2026-39892 is a buffer overflow vulnerability in the Python cryptography package versions 45.0.0 through 46.0.6. The flaw occurs when non-contiguous buffers are passed to APIs accepting Python buffers, such as the Hash.update() function, potentially allowing memory corruption. This vulnerability has been remediated in version 46.0.7 and later. The vulnerability carries a CVSS score of 9.8 (CRITICAL), reflecting a network-accessible attack vector with low complexity and no authentication requirements. An unauthenticated remote attacker could potentially exploit this issue without user interaction to compromise confidentiality, integrity, and availability of affected systems. The FAUCET Risk Score of 55.0/100 indicates moderate overall risk considering multiple risk factors. There is currently no evidence of active exploitation in the wild, with the vulnerability not appearing on the CISA Known Exploited Vulnerabilities (KEV) list. The Exploit Prediction Scoring System (EPSS) score of 0.00021 suggests minimal probability of near-term exploitation. This vulnerability should nonetheless be treated as priority for patching given its critical severity rating, particularly for systems handling cryptographic operations where buffer overflows could have significant consequences.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 45.0.0, < 46.0.7CPE matchmatch criteria | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.