Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0031 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised. |
Github GHSA |
GHSA-6vqw-3v5j-54x4 | cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override |
Ubuntu USN |
USN-6673-1 | python-cryptography vulnerabilities |
Ubuntu USN |
USN-6673-3 | python-cryptography vulnerability |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhui
|
|
| CPEs | cpe:/a:redhat:rhui:4::el8 | |
| Vendors & Products |
Redhat rhui
|
Wed, 05 Feb 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cryptography.io
Cryptography.io cryptography |
|
| CPEs | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Cryptography.io
Cryptography.io cryptography |
Fri, 11 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat satellite
Redhat satellite Capsule |
|
| CPEs | cpe:/a:redhat:satellite:6.15::el8 cpe:/a:redhat:satellite_capsule:6.15::el8 |
|
| Vendors & Products |
Redhat satellite
Redhat satellite Capsule |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-14T20:01:52.628Z
Reserved: 2024-02-14T17:40:03.687Z
Link: CVE-2024-26130
Updated: 2024-08-01T23:59:32.542Z
Status : Analyzed
Published: 2024-02-21T17:15:09.863
Modified: 2025-02-05T22:09:20.427
Link: CVE-2024-26130
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN