CVE-2026-39892: Cryptography.io Cryptography
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
Affected products
- Cryptography.io Cryptography: from 45.0.0, before 46.0.7 (fixed in 46.0.7)
Published 2026-04-08. Last modified 2026-09-10.