© 2025-2026 PySpect
First version without a known vulnerability: 50.0.0
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
Fixed in: 49.0.0
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
Fixed in: 49.0.0
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
Fixed in: 50.0.0
Vulnerable OpenSSL included in cryptography wheels
Fixed in: 48.0.1
Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs
Fixed in: 46.0.7
cryptography has incomplete DNS name constraint enforcement on peer names
Fixed in: 46.0.6
cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
Fixed in: 46.0.5
Vulnerable OpenSSL included in cryptography wheels
Fixed in: 44.0.1
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
Fixed in: 43.0.1
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
Fixed in: 42.0.4, 97d231672763cdb5959a3b191e692a362f1b9e55
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
Fixed in: 42.0.0
Null pointer dereference in PKCS12 parsing
Fixed in: 42.0.2
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
Fixed in: 41.0.6, f09c261ca10a31fe41b1262306db7f8f1da0e48a
Vulnerable OpenSSL included in cryptography wheels
Fixed in: 41.0.4
pyca/cryptography's wheels include vulnerable OpenSSL
Fixed in: 41.0.3
cryptography mishandles SSH certificates
Fixed in: 41.0.2
Vulnerable OpenSSL included in cryptography wheels
Fixed in: 41.0.0
Vulnerable OpenSSL included in cryptography wheels
Fixed in: 39.0.1, 111.25.0, 300.0.12
Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
Fixed in: 39.0.1, 94a50a9731f35405f0357fa5f3b177d46a726ab3
Vulnerable OpenSSL included in cryptography wheels
Fixed in: 38.0.3
Improper input validation in cryptography
Fixed in: 1.5.3, b924696b2e8731f39696584d12cceeb3aeb2d874
PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
Fixed in: 3.3.2
RSA decryption vulnerable to Bleichenbacher timing vulnerability
Fixed in: 3.2, 3.2.1
PyCA Cryptography vulnerable to GCM tag forgery
Fixed in: 2.3