Cryptography
Vendor:
First CVE: Mar 27, 2017 · Active for 9 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cryptography over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 27, 2017
9 years ago
Most Recent CVE
Apr 8, 2026
107 days ago
CVE Severity & Scoring
Cryptography11 CVEs
36%
45%
18%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39892CRITICAL cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs | Apr 8, 2026 | 9.8 | 40 | NO | NO |
CVE-2020-36242CRITICAL In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overf | Feb 7, 2021 | 9.1 | 31 | NO | NO |
CVE-2026-26007MEDIUM cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers. | Feb 10, 2026 | 6.5 | 29 | NO | NO |
CVE-2023-49083HIGH cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could | Nov 29, 2023 | 7.5 | 24 | NO | NO |
CVE-2026-34073MEDIUM cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SA | Mar 31, 2026 | 5.3 | 23 | NO | NO |
CVE-2024-26130HIGH cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize | Feb 21, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-50782HIGH A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead t | Feb 5, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-23931MEDIUM cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which | Feb 7, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-38325HIGH The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. | Jul 14, 2023 | 7.5 | 21 | NO | NO |
CVE-2016-9243HIGH HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size. | Mar 27, 2017 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Cryptography
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2 | 1 | 5.9 | 2.5% | 0 | 0 |