CVE-2023-49083

Aliases:GHSA-jfhm-5ghh-2f97PYSEC-2023-254DEBIAN-CVE-2023-49083RHSA-2024:10965RHSA-2024:2337RHSA-2024:3105RHSA-2025:13098RHSA-2025:13100RHSA-2025:13101RHSA-2025:13102RHSA-2025:13103RHSA-2025:13104RHSA-2025:14553RHSA-2025:15874CGA-92g2-p386-66hhCGA-jjpj-h9m7-2jppCGA-r75f-gxwh-xmcqCGA-vgxr-27q9-mm4cCGA-w7x4-gq7g-4p29CGA-x2mv-c8j8-922v
Modified
Published: 29 Nov 2023, 18:50
Last modified:18 Dec 2025, 15:32

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.98% LOW
1% probability -0.27%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

29 Nov 2023, 18:50
Published
Vulnerability first disclosed
18 Dec 2025, 15:32
Last Modified
Vulnerability information updated

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.98% Percentile: 61%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • chainguardmitmproxy

    < 12.2.1-r0

  • chainguardpy3-cassandra-medusa

    < 0.19.1-r1

  • chainguardpy3-cassandra-medusa-compat

    < 0.19.1-r1

  • wolfimitmproxy

    < 12.2.1-r0

  • wolfipy3-cassandra-medusa

    < 0.19.1-r1

  • wolfipy3-cassandra-medusa-compat

    < 0.19.1-r1

  • cryptography.iocryptography

    ≥ 3.1, < 41.0.6

  • debianpython-cryptography

    < 3.3.2-1+deb11u1 | < 38.0.4-3+deb12u1 | < 41.0.7-1 | < 41.0.7-1

  • pycacryptography

    ≥ 3.1, < 41.0.6

  • PyPIcryptography

    < f09c261ca10a31fe41b1262306db7f8f1da0e48a | ≥ 3.1, < 41.0.6

  • redhatpython-cryptography

    < 0:3.2.1-4.el8_4.1 | < 0:3.2.1-6.el8_8 | < 0:36.0.1-2.el9_2.1 | < 0:36.0.1-1.el9_0.1 | < 0:36.0.1-4.el9_4.1 | < 0:3.2.1-5.1.el8_6.1 | < 0:3.2.1-8.el8_10 | < 0:36.0.1-5.el9_6

  • redhatpython-cryptography-debugsource

    < 0:3.2.1-4.el8_4.1 | < 0:3.2.1-6.el8_8 | < 0:36.0.1-2.el9_2.1 | < 0:36.0.1-1.el9_0.1 | < 0:36.0.1-4.el9_4.1 | < 0:3.2.1-5.1.el8_6.1 | < 0:3.2.1-8.el8_10 | < 0:36.0.1-5.el9_6

  • redhatpython3-cryptography

    < 0:3.2.1-4.el8_4.1 | < 0:3.2.1-6.el8_8 | < 0:36.0.1-2.el9_2.1 | < 0:36.0.1-1.el9_0.1 | < 0:36.0.1-4.el9_4.1 | < 0:3.2.1-5.1.el8_6.1 | < 0:3.2.1-8.el8_10 | < 0:36.0.1-5.el9_6

  • redhatpython3-cryptography-debuginfo

    < 0:3.2.1-4.el8_4.1 | < 0:3.2.1-6.el8_8 | < 0:36.0.1-2.el9_2.1 | < 0:36.0.1-1.el9_0.1 | < 0:36.0.1-4.el9_4.1 | < 0:3.2.1-5.1.el8_6.1 | < 0:3.2.1-8.el8_10 | < 0:36.0.1-5.el9_6

  • redhatpython3.11-cryptography

    < 0:37.0.2-5.el8_8.1 | < 0:37.0.2-6.el9 | < 0:37.0.2-6.el8

  • redhatpython3.11-cryptography-debuginfo

    < 0:37.0.2-5.el8_8.1 | < 0:37.0.2-6.el9 | < 0:37.0.2-6.el8

  • redhatpython3.11-cryptography-debugsource

    < 0:37.0.2-5.el8_8.1 | < 0:37.0.2-6.el9 | < 0:37.0.2-6.el8

References (40)