CVE-2026-39892
Vulnerability Summary
Timeline
Description
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.
CVSS Metrics
- v4.0•MEDIUM•Score: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- v4.0•MEDIUM•Score: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- v3.1•HIGH•Score: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.65%• Percentile: 50%
Techniques & Countermeasures
- CWE-119•Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
- CWE-131•Incorrect Calculation of Buffer Size
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Affected Systems
- alpine•py3-cryptography
≥ 45.0.0, < 46.0.7-r0 | ≥ 45.0.0, < 46.0.7-r0
- chainguard•airflow-2
< 2.11.2-r8
- chainguard•airflow-3
< 3.2.0-r1
- chainguard•airflow-core-2
< 2.11.2-r5
- chainguard•airflow-core-3
< 3.2.0-r2
- chainguard•apache-beam-python-3.11-sdk
< 2.73.0-r6
- chainguard•apache-beam-python-3.12-sdk
< 2.72.0-r2
- chainguard•apache-beam-python-3.13-sdk
< 2.73.0-r4
- chainguard•authentik-2025.12
< 2025.12.4-r3
- chainguard•authentik-2026.2
< 2026.2.1-r3
- chainguard•barman-cloudnative-pg
< 3.18.0-r2
- chainguard•dagster
< 1.13.2-r0
- chainguard•dask-kubernetes
< 2026.3.0-r3
- chainguard•datadog-agent-7.71-core-integrations
< 7.71.2-r26
- chainguard•datadog-agent-7.72-core-integrations
< 7.72.4-r27
- chainguard•datadog-agent-7.73-core-integrations
< 7.73.3-r23
- chainguard•datadog-agent-7.74-core-integrations
< 7.74.1-r19
- chainguard•datadog-agent-7.75-core-integrations
< 7.75.4-r6
- chainguard•datadog-agent-fips-7.71-core-integrations
< 7.71.2-r20
- chainguard•datadog-agent-fips-7.72-core-integrations
< 7.72.4-r18
- chainguard•datadog-agent-fips-7.73-core-integrations
< 7.73.3-r17
- chainguard•datadog-agent-fips-7.74-core-integrations
< 7.74.1-r16
- chainguard•datadog-agent-fips-7.75-core-integrations
< 7.75.4-r4
- chainguard•dbt-snowflake
all | < 1.10.4-r4
- chainguard•ggshield
< 1.51.0-r5
- chainguard•gitlab-toolbox-ce-18.7
all
- chainguard•gitlab-toolbox-ce-fips-18.7
< 18.7.6-r2
- chainguard•in-toto
< 3.1.0-r0
- chainguard•jupyter-base-notebook
< 7.5.5-r4
- chainguard•k8s-sidecar
< 2.6.0-r0
- chainguard•kserve-storage-controller
< 0.16.0-r25
- chainguard•kubeflow-jupyter-web-app
< 1.10.0-r15
- chainguard•kubeflow-pipelines-visualization-server
< 2.16.0-r4
- chainguard•kubeflow-volumes-web-app
< 1.10.0-r16
- chainguard•label-studio
< 1.23.0-r3
- chainguard•localstack
< 4.14.0-r8
- chainguard•metaflow-service
< 2.5.0-r10
- chainguard•mitmproxy
< 12.2.2-r1
- chainguard•mlflow
< 3.16.0-r0
- chainguard•mycli
< 1.68.1-r0
- chainguard•nemo
< 2.7.2-r2
- chainguard•opal
< 0.9.4-r2
- chainguard•open-webui
< 0.8.12-r3
- chainguard•openstack-kolla-toolbox-2025.1
< 20.4.0-r5
- chainguard•openstack-kolla-toolbox-2025.2
< 21.1.0-r3
- chainguard•pgadmin4
< 9.14-r1
- chainguard•pgadmin4-fips
< 9.14-r1
- chainguard•py3-cassandra-medusa
< 0.27.1-r2
- chainguard•py3.11-prefect
< 3.7.3-r0
- chainguard•py3.12-prefect
< 3.7.3-r0
Showing first 50 affected entries in server-rendered view.
References (36)
- https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq
- https://github.com/pyca/cryptography
- http://www.openwall.com/lists/oss-security/2026/04/08/12
- https://nvd.nist.gov/vuln/detail/CVE-2026-39892
- https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-36.yaml
- https://access.redhat.com/security/cve/CVE-2026-39892
- https://bugzilla.redhat.com/show_bug.cgi?id=2456735
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39892.json
- https://access.redhat.com/errata/RHSA-2026:24761
- https://access.redhat.com/errata/RHSA-2026:24762
- https://access.redhat.com/errata/RHSA-2026:30089
- https://access.redhat.com/errata/RHSA-2026:30088
- https://access.redhat.com/errata/RHSA-2026:24866
- https://access.redhat.com/errata/RHSA-2026:20338
- https://access.redhat.com/errata/RHSA-2026:7295
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/errata/RHSA-2026:22629
- https://access.redhat.com/errata/RHSA-2026:21017
- https://access.redhat.com/errata/RHSA-2026:24853
- https://access.redhat.com/errata/RHSA-2026:19375
- https://access.redhat.com/errata/RHSA-2026:22465
- https://access.redhat.com/errata/RHSA-2026:22840
- https://access.redhat.com/errata/RHSA-2026:23361
- https://access.redhat.com/errata/RHSA-2026:24483
- https://access.redhat.com/errata/RHSA-2026:37275
- https://access.redhat.com/errata/RHSA-2026:42644
- https://access.redhat.com/errata/RHSA-2026:43855
- https://access.redhat.com/errata/RHSA-2026:43854
- https://access.redhat.com/errata/RHSA-2026:43851
- https://access.redhat.com/errata/RHSA-2026:43670
- https://access.redhat.com/errata/RHSA-2026:43853
- https://access.redhat.com/errata/RHSA-2026:43651
- https://access.redhat.com/errata/RHSA-2026:46956
- https://security-tracker.debian.org/tracker/CVE-2026-39892
- https://security.alpinelinux.org/vuln/CVE-2026-39892
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39892.json