Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi cryptography Security Advisories

Loading...
High
GSA_kwCzR0hTQS02dnF3LTN2NWotNTR4NM4AA5bN
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 38.4
Published: 2 months ago
High
GSA_kwCzR0hTQS0zd3c0LWdnNGYtanI3Zs4AA5Eq
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 38.4
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS05djloLWNnajgtaDY0cM4AA44M
Null pointer dereference in PKCS12 parsing
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 28.2
Published: 3 months ago
Moderate
GSA_kwCzR0hTQS1qZmhtLTVnaGgtMmY5N84AA3Zw
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 30.2
Published: 5 months ago
Low
GSA_kwCzR0hTQS12OGdyLW01MzMtZ2hqOc4AA1_w
Vulnerable OpenSSL included in cryptography wheels
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 7 months ago
Low
GSA_kwCzR0hTQS1qbTc3LXFwaGYtYzR3OM4AA0_V
pyca/cryptography's wheels include vulnerable OpenSSL
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 9 months ago
High
GSA_kwCzR0hTQS1jZjdwLWdtMm0tODMzbc4AA0t4
cryptography mishandles SSH certificates
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 38.4
Published: 10 months ago
Low
GSA_kwCzR0hTQS01Y3BxLTh3ajctaGYyds4AAzmB
Vulnerable OpenSSL included in cryptography wheels
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: 11 months ago
High
GSA_kwCzR0hTQS14NHFyLTJmdmYtM21yNc4AAxfn
Vulnerable OpenSSL included in cryptography wheels
Ecosystems: cargo, pypi
Packages: openssl-src, cryptography
Source: GitHub Advisory Database
Blast Radius: 64.2
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS13N3BwLW04d2Ytdmo2cs4AAxeE
Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 33.3
Published: about 1 year ago
Moderate
GSA_kwCzR0hTQS0zOWhjLXY4N2otNzQ3eM4AAvq8
Vulnerable OpenSSL included in cryptography wheels
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 0.0
Published: over 1 year ago
High
GSA_kwCzR0hTQS1xM2NqLTJyMzQtMmN3Y84AAbxz
Improper input validation in cryptography
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 38.4
Published: almost 2 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJobTktcDl3NS1md203
PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 46.6
Published: about 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhnZ20tanBnMy12NDc2
RSA decryption vulnerable to Bleichenbacher timing vulnerability
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 30.2
Published: over 3 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZjZjktM3F3My1neG1q
PyCA Cryptography vulnerable to GCM tag forgery
Ecosystems: pypi
Packages: cryptography
Source: GitHub Advisory Database
Blast Radius: 38.4
Published: almost 6 years ago
Statistics
Advisories: 18,317
Packages: 8,278
Repositories: 2
Ecosystems: 12
Filter by Package
tensorflow 432 tensorflow-cpu 387 tensorflow-gpu 384 django 80 apache-airflow 78 ansible 63 salt 50 apache-superset 48 Plone 45 plone 43 rdiffweb 42 Pillow 41 vyper 38 matrix-synapse 35 mlflow 31 opencv-contrib-python 30 opencv-python 30 Django 27 moin 23 langchain 18 PaddlePaddle 17 cobbler 17 mercurial 17 pillow 16 notebook 15 cryptography 15 nova 15 paddlepaddle 15 pyftpdlib 14 gradio 14 pyload-ng 14 modoboa 14 keystone 14 neutron 13 vantage6 12 OctoPrint 12 twisted 11 calibreweb 11 onionshare-cli 11 glance 11 urllib3 11 wagtail 10 trytond 10 Flask-AppBuilder 10 aiohttp 10 opencv-python-headless 9 opencv-contrib-python-headless 9 kiwitcms 9 Zope 9 waitress 9 ethyca-fides 9 zope 9 nautobot 8 label-studio 8 numpy 8 trac 8 python-keystoneclient 8 roundup 8 aubio 8 pysaml2 7 pip 7 matrix-sydent 7 ipython 7 swift 7 lief 7 jupyter-server 7 scrapy 7 sentry 6 graphite-web 6 lxml 6 web2py 6 apache-airflow-providers-apache-hive 6 tuf 6 pgadmin4 6 Zope2 6 mindsdb 6 inventree 6 horizon 6 mailman 6 Products.CMFPlone 5 lmdb 5 bleach 5 pyspark 5 whoogle-search 5 requests 5 ckan 5 paramiko 5 feedparser 5 saleor 5 cinder 5 python-gnupg 5 Pygments 4 jwcrypto 4 ansible-core 4 jupyterhub 4 awsiotsdk 4 GitPython 4 bottle 4 tornado 4 FreeTAKServer-UI 4 markdown2 4 datasette 4 Jinja2 4 reportlab 4 nltk 4 werkzeug 4 nvflare 4 httpie 4 omero-web 4 pretix 4 tripleo-heat-templates 4 yt-dlp 4 keylime 4 PyPDF2 4 grpc 4 Flask-Security-Too 4 transformers 4 qutebrowser 4 grpcio 4 aws-iot-device-sdk-v2 4 Radicale 4 starlette 4 buildbot 4 oauthenticator 4 esphome 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 dulwich 3 Products.PluggableAuthService 3 asyncua 3 indy-node 3 ansible-runner 3 onnx 3 fava 3 rsa 3 apache-iotdb 3 gerapy 3 jupyterlab 3 keyring 3 ecdsa 3 pandasai 3 python-jose 3 ray 3 mayan-edms 3 asyncssh 3 pyarrow 3 pywasm3 3 ajenti 3 mistune 3 protobuf 3 sanic 3 indico 3 poetry 3 barbican 3 wger 3 io.grpc:grpc-protobuf 3 flask 3 Werkzeug 3 copyparty 3 bitlyshortener 3 localstack 3 clearml 3 pyyaml 3 docassemble.webapp 3 SQLAlchemy 3 openvpn-monitor 3 sosreport 3 homeassistant 3 quokka 3 sqlparse 3 apache-libcloud 3 Keystone 3 sickrage 3 zenml 3 Mezzanine 3 django-helpdesk 3 pycrypto 3 mitmproxy 3 Moin 3 torchserve 3 streamlit 3 plone.app.event 3 plone.app.theming 3 plone.app.dexterity 3 plone.supermodel 3 apache-airflow-providers-apache-spark 3 aim 3 httplib2 3 octavia 3 slixmpp 3 ryu 3 scipy 3 Weblate 3 ujson 3 Red-DiscordBot 2 sap-xssec 2 keystonemiddleware 2 borgbackup 2 pyxdg 2 untangle 2 logilab-common 2