Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p423-j2cm-9vmq | Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs |
Wed, 15 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cryptography.io
Cryptography.io cryptography |
|
| CPEs | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Cryptography.io
Cryptography.io cryptography |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 10 Apr 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-131 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pyca
Pyca cryptography |
|
| Vendors & Products |
Pyca
Pyca cryptography |
Wed, 08 Apr 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 08 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. | |
| Title | cryptography has a buffer overflow if non-contiguous buffers were passed to APIs | |
| Weaknesses | CWE-119 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-09T19:52:22.602Z
Reserved: 2026-04-07T20:32:03.011Z
Link: CVE-2026-39892
Updated: 2026-04-08T21:16:07.164Z
Status : Analyzed
Published: 2026-04-08T21:17:01.547
Modified: 2026-04-15T16:12:39.677
Link: CVE-2026-39892
OpenCVE Enrichment
Updated: 2026-04-10T09:40:32Z
Github GHSA