VYPR
Critical severity9.8NVD Advisory· Published Apr 8, 2026· Updated Apr 15, 2026

CVE-2026-39892

CVE-2026-39892

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
cryptographyPyPI
>= 45.0.0, < 46.0.746.0.7

Affected products

75

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.