CVE-2026-34073Disclosure(cryptography.io / cryptography)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cryptography.io cryptography systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cryptography

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-31); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Products
cryptography

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-30: 1Mentions · 2026-03-31: 5Mentions · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 3Technical Details · 2026-07-09: 103-3003-3107-09
Signal classification3 categories
Disclosure
342.9%
General
342.9%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-301
Disclosure1
2026-03-315
Disclosure2General3
2026-07-091
Patch1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-34073: pyca/cryptography: X.509: bypass of name constraints on wildcard SANs with matching peer names https://www.openwall.com/lists/oss-security/2026/03/30/8 bar.example.⁠com could validate against cert for *.example.com despite an excluded subtree constraint for bar.example.⁠com in parent or upwards

    Post summary

    CVE‑2026‑34073 exposes a name‑constraint bypass in pyca/cryptography's X.509 handling, allowing a certificate for *.example.com to validate for bar.example.com despite an excluded subtree constraint. No active exploitation, PoC, or patch details are disclosed.

    01063469
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34073 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only valida… https://www.cve.org/CVERecord?id=CVE-2026-34073

    Post summary

    The excerpt identifies CVE-2026-34073 as a DNS name constraint validation issue in the cryptography Python package before version 46.0.6, but it offers no proof of exploitation, patch, or detailed mitigations.

    0000181
    56.9K followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    New critical CVEs in 'cryptography' (CVE-2024-12797, CVE-2026-26007, CVE-2026-34073, July 8) expose TLS/DNS to MITM & forgery. Immediate patching vital for data privacy & integrity in transit. #Cybersecurity #News

    Post summary

    The post reports newly discovered critical cryptography CVEs that expose TLS/DNS to MITM and forgery, emphasizing the need for immediate patching to protect data privacy and integrity.

    0000087
    14 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-34073 📊 Severity: 1.7 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34073 #CVE-2026-34073 #CVE #Low #CyberSecurity #InfoSec https://t.co/LCV7Q40GR8

    Post summary

    The tweet simply announces CVE-2026-34073 with a low severity score and no further technical or mitigation details.

    0000024
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34073 - cryptography has incomplete DNS name constraint enforcement on peer names Intel Report: https://ift.tt/8GHSh0O

    Post summary

    The post references CVE‑2026‑34073, noting a flaw in cryptography’s DNS name constraint enforcement, but offers no proof‑of‑concept, exploit, patch, or evidence of active exploitation.

    0000041
    281 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-34073 pyca/cryptography https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34073

    Post summary

    The entry merely references CVE‑2026‑34073 for the pyca/cryptography project and links to a vulnerability details page, without providing technical, exploit, or patch information.

    0000041
    4.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 BREAKING: CVE-2026-34073 affects #python-cryptography <46.0.5 . Read more: 👉 https://tinyurl.com/2s3vptvc #Security #Fedora https://t.co/gCXmBya9Ix

    Post summary

    The tweet announces CVE-2026-34073, noting it affects python‑cryptography versions below 46.0.5, but provides no further details on PoC, exploitation, or remediation.

    0000047
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcryptography.iocryptography-python-

Explore more