
CVE-2026-39892: PyCA cryptography: Non-contiguous buffers could be passed to APIs that accept Python buffers, which could lead to buffer overflow https://www.openwall.com/lists/oss-security/2026/04/08/12 h = Hash(SHA256()) b.update(buf[::-1]) would read past the end of the buffer on Python >3.11 Fixed in 46.0.7
Post summary
The post announces a buffer‑overflow vulnerability in PyCA cryptography, details the issue, and notes that the problem was fixed in version 46.0.7, with no evidence of exploitation or a PoC.




