Critical severity9.8NVD Advisory· Published Apr 8, 2026· Updated Apr 15, 2026
CVE-2026-39892
CVE-2026-39892
Description
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cryptographyPyPI | >= 45.0.0, < 46.0.7 | 46.0.7 |
Affected products
1- cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*Range: >=45.0.0,<46.0.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.openwall.com/lists/oss-security/2026/04/08/12nvdMailing ListRelease NotesThird Party AdvisoryWEB
- github.com/advisories/GHSA-p423-j2cm-9vmqghsaADVISORY
- github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmqnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-39892ghsaADVISORY
News mentions
30- In Other News: Big Tech vs Canada Encryption Bill, Cisco’s Free AI Security Spec, Audi App FlawsSecurityWeek · May 15, 2026
- Cyber Pioneers Ponder Past as PrologueDark Reading · May 15, 2026
- Bypassing On-Camera Age-Verification ChecksSchneier on Security · May 15, 2026
- Android Adds Intrusion Logging for Sophisticated Spyware ForensicsThe Hacker News · May 13, 2026
- Android pushes new scam, theft, and AI protections in 2026 update waveHelp Net Security · May 13, 2026
- Android 17 to expand banking scam call and privacy protectionsBleepingComputer · May 12, 2026
- 20 Leaders Who Built the CISO Era: 2 Decades of ChangeDark Reading · May 12, 2026
- State of ransomware in 2026Securelist · May 12, 2026
- Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and ToolsUnit 42 · May 11, 2026
- Tech Can't Stop These Threats — Your People CanDark Reading · May 11, 2026
- Red Hat extends open source technology into spaceHelp Net Security · May 11, 2026
- ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreThe Hacker News · May 11, 2026
- Review: Foundations of Cybersecurity, 2nd editionHelp Net Security · May 11, 2026
- Friday Squid Blogging: Giant Squid Live in the Waters of Western AustraliaSchneier on Security · May 8, 2026
- Google is turning Android Studio into a policy watchdogHelp Net Security · May 8, 2026
- ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New StoriesThe Hacker News · May 7, 2026
- Red Hat Enterprise Linux adds post-quantum security and AI-driven automation in latest releasesHelp Net Security · May 7, 2026
- Proton Mail brings quantum-safe email encryption to all accountsHelp Net Security · May 6, 2026
- VIAVI CyberFlood CF1000 pushes 400G validation for multi-terabit AI data centersHelp Net Security · May 5, 2026
- Another AI-Assisted Software Scan Yields 9-Year-Old Linux BugDark Reading · Apr 30, 2026
- Post-quantum encryption for Cloudflare IPsec is generally availableCloudflare Blog · Apr 30, 2026
- Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and IndiaSecurelist · Apr 30, 2026
- DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the ProxyCheck Point Research · Apr 20, 2026
- Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software VulnerabilitiesInfosecurity Magazine · Apr 8, 2026
- Quantum Computing Threat to Encryption Is Closer Than Expected, Warns GoogleInfosecurity Magazine · Mar 27, 2026
- UK: Regulation Drives Cyber Spending for Critical Infrastructure OrgsInfosecurity Magazine · Mar 19, 2026
- Infosecurity Europe Announces 2026 Keynote Line UpInfosecurity Magazine · Mar 11, 2026
- Sednit reloaded: Back in the trenchesESET WeLiveSecurity · Mar 10, 2026
- Trump Administration Unveils New Cyber Strategy for AmericaInfosecurity Magazine · Mar 9, 2026
- PromptSpy ushers in the era of Android threats using GenAIESET WeLiveSecurity · Feb 19, 2026