CVE-2012-4571: Python Keyring

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

Affected products

  • Python Keyring: version 0.9.1 only

Published 2012-11-30. Last modified 2026-06-16.