CVE-2026-39892: Cryptography.io Cryptography

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

Affected products

Published 2026-04-08. Last modified 2026-09-10.