CVE Tools

Cryptography

24 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Cryptography, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Cryptography CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Cryptography CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-031
2026-041
2026-050
2026-061
2026-070
2026-083
2026-090

Severity

How the 24 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical213%
  • High640%
  • Medium747%

Latest CVEs

The 15 most recently published vulnerabilities affecting Cryptography.

  1. CVE-2026-69249python-cryptography: Duplicate self-signed intermediates can cause exponential path-building—
  2. CVE-2026-69248python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees—
  3. CVE-2026-69247cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing—
  4. GHSA-537c-gmf6-5ccfVulnerable OpenSSL included in cryptography wheels—
  5. CVE-2026-39892cryptography has a buffer overflow if non-contiguous buffers were passed to APIs9.8
  6. CVE-2026-34073cryptography has incomplete DNS name constraint enforcement on peer names5.3
  7. CVE-2026-26007cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves6.5
  8. CVE-2024-12797RFC7250 handshakes with unauthenticated servers don't abort as expected6.3
  9. GHSA-h4gh-qq45-vh27pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels—
  10. CVE-2024-26130cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override7.5
  11. CVE-2023-50782Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-256597.5
  12. CVE-2024-0727PKCS12 Decoding crashes5.5
  13. CVE-2023-49083cryptography vulnerable to NULL-dereference when loading PKCS7 certificates5.9
  14. GHSA-v8gr-m533-ghj9Vulnerable OpenSSL included in cryptography wheels—
  15. GHSA-jm77-qphf-c4w8pyca/cryptography's wheels include vulnerable OpenSSL—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store