CVE-2026-39892

EUVD-2026-20640
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 48.59%
Affected Products (NVD)
VendorProductVersion
cryptography.iocryptography
45.0.0 ≤
𝑥
< 46.0.7
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
0:4.6.29-2.el8ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
0:46.0.7-1.el8ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
0:4.6.29-2.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
0:46.0.7-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
0:4.7.12-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
0:46.0.7-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782353093 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782352847 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1779762270 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1779759716 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1779734628 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1779773804 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1779761061 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1779760844 ≤
𝑥
< *
ADP
Red HatRed Hat Discovery 2
1779395228 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux AI 3.3
1784670204 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux AI 3.3
1784669680 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux AI 3.3
1784736822 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux AI 3.3
1784736941 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux AI 3.3
1784736798 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux AI 3.3
1784736857 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux AI 3.3
1785163184 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
46.0.7-1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1780069069 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1783701598 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782471587 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782472374 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782471606 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.1
1779822261 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.12
1779811412 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.14
1779689392 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.15
1780891395 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.16
1779204086 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.17
1779922205 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.9
1779811473 ≤
𝑥
< *
ADP
Red HatRed Hat Trusted Artifact Signer 1.4
1780914886 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
python-cryptography
bookworm
38.0.4-3+deb12u1
fixed
bookworm (security)
38.0.4-3~deb12u1
fixed
bullseye
3.3.2-1
fixed
bullseye (security)
3.3.2-1+deb11u1
fixed
forky
49.0.0-2
fixed
sid
49.0.0-2
fixed
trixie
43.0.0-3+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-cryptography
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
xenial
not-affected
References