CVE-2026-39892General(cryptography.io / cryptography)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cryptography.io cryptography systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-131

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cryptography

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-08); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
cryptography

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-08: 2Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-18: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 104-0804-0904-1004-18
Signal classification3 categories
General
240.0%
Patch
240.0%
Disclosure
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-082
General2
2026-04-091
Disclosure1
2026-04-101
Patch1
2026-04-181
Patch1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-39892: PyCA cryptography: Non-contiguous buffers could be passed to APIs that accept Python buffers, which could lead to buffer overflow https://www.openwall.com/lists/oss-security/2026/04/08/12 h = Hash(SHA256()) b.update(buf[::-1]) would read past the end of the buffer on Python >3.11 Fixed in 46.0.7

    Post summary

    The post announces a buffer‑overflow vulnerability in PyCA cryptography, details the issue, and notes that the problem was fixed in version 46.0.7, with no evidence of exploitation or a PoC.

    01061901
    4.6K followersView on X
  • RazzReport@RazzReport
    Patch

    OpenHands/OpenHands patched CVE-2026-39892, a critical vulnerability for autonomous code-execution agents. Also shipped settings preservation fixes. Essential security update for production.

    Post summary

    OpenHands released a patch for CVE-2026-39892, a critical vulnerability affecting autonomous code‑execution agents, without any mention of PoC, exploit code, or active exploitation.

    1000060
    5 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 #Python cryptography, Buffer Overflow, #CVE-2026-39892 (Moderate) https://dailycve.com/python-cryptography-buffer-overflow-cve-2026-39892-moderate/

    Post summary

    The tweet announces CVE-2026-39892, describing a buffer overflow in Python cryptography with moderate severity, but provides no PoC, exploit code, or patch information.

    0000028
    178 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-39892 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was p… https://www.cve.org/CVERecord?id=CVE-2026-39892 ----- Traducción: CVE-2026-39892 cri… http://infoflow.cloud`

    Post summary

    The tweet merely links to the CVE record with minimal context, providing no additional information about exposure, exploitation, or mitigation.

    0000023
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-39892 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was p… https://www.cve.org/CVERecord?id=CVE-2026-39892

    Post summary

    The statement merely references CVE‑2026‑39892 and links to the CVE record, providing no additional detail on exploitation, mitigation, or technical specifics.

    00000154
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcryptography.iocryptography-python-

Explore more