Vulnerabilidades en pyca
11 resultadosAnálisis Vexday
A pyca possui 11 vulnerabilidades registradas, com 3 publicadas nos últimos 90 dias, indicando atividade recente de descoberta. Nenhuma está sob exploração ativa conhecida (KEV) e não há críticas de severidade máxima, reduzindo o risco imediato. A fraqueza dominante é validação inadequada de certificados (CWE-295), típica de bibliotecas criptográficas, exigindo atenção em ambientes que dependem de verificação de identidade.
CVE-2023-23931MEDIUMCipher.update_into can corrupt memory in pyca cryptographyEPSS 1.3%CVE-2023-49083MEDIUMcryptography vulnerable to NULL-dereference when loading PKCS7 certificatesEPSS 1.0%CVE-2024-26130HIGHcryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash overrideEPSS 0.8%CVE-2026-27459HIGHpyOpenSSL DTLS cookie callback buffer overflowEPSS 0.7%CVE-2026-39892MEDIUMcryptography has a buffer overflow if non-contiguous buffers were passed to APIsEPSS 0.7%CVE-2026-26007HIGHcryptography Subgroup Attack Due to Missing Subgroup Validation for SECT CurvesEPSS 0.3%CVE-2026-27448LOWpyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callbackEPSS 0.2%CVE-2026-69249HIGHpython-cryptography: Duplicate self-signed intermediates can cause exponential path-buildingEPSS 0.2%CVE-2026-69248MEDIUMpython-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtreesEPSS 0.2%CVE-2026-69247HIGHcryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timingEPSS 0.2%CVE-2026-34073LOWcryptography has incomplete DNS name constraint enforcement on peer namesEPSS 0.2%