The Cryptography.io project maintains a widely embedded Python cryptographic library that, despite a narrow product focus, serves as a foundational dependency across numerous applications and frameworks handling sensitive data operations. Vulnerabilities affecting the vendor skew toward serious outcomes, with a notable share reaching critical severity, and recur through weakness classes including improper certificate validation, NULL-pointer dereferences, timing-channel leaks, and memory-bounds violations that reflect the low-level parsing and constant-time operation demands of cryptographic implementations. Defenders should treat this library's advisories as high-priority across their supply chain rather than tracking the library alone, since remediation depends on downstream projects rebuilding; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cryptography.Io over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39892CRITICAL cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs | Apr 8, 2026 | 9.8 | 40 | NO | NO |
CVE-2020-36242CRITICAL In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overf | Feb 7, 2021 | 9.1 | 31 | NO | NO |
CVE-2026-26007MEDIUM cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers. | Feb 10, 2026 | 6.5 | 29 | NO | NO |
CVE-2023-49083HIGH cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could | Nov 29, 2023 | 7.5 | 24 | NO | NO |
CVE-2026-34073MEDIUM cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SA | Mar 31, 2026 | 5.3 | 23 | NO | NO |
CVE-2024-26130HIGH cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize | Feb 21, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-50782HIGH A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead t | Feb 5, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-23931MEDIUM cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which | Feb 7, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-38325HIGH The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. | Jul 14, 2023 | 7.5 | 21 | NO | NO |
CVE-2016-9243HIGH HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size. | Mar 27, 2017 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cryptography.Io.
Media articles that mention a CVE ID that affects a product developed by Cryptography.Io — matched by CVE ID, not by vendor name.