[pkg-vuln] CVE-2026-39892 in cryptography@46.0.5 #332

Closed
opened 2026-04-09 06:01:05 +00:00 by kert · 0 comments
Owner

Severity: MEDIUM
Package: cryptography @ 46.0.5
Fixed in: 46.0.7

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-39892

**Severity:** MEDIUM **Package:** `cryptography` @ `46.0.5` **Fixed in:** `46.0.7` cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-39892
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-04-09 06:01:05 +00:00
kert added the qualityci labels 2026-04-09 06:01:05 +00:00
kert closed this issue 2026-04-10 00:57:10 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#332