CVE-2026-69249

Aliases:GHSA-jwv3-5hgf-82wwPYSEC-2026-3553UBUNTU-CVE-2026-69249DEBIAN-CVE-2026-69249CGA-2254-h994-q8frCGA-3g89-jqc3-4r6qCGA-h763-vvvj-pf9xCGA-255m-9cff-p7v5CGA-2wvf-qp8m-8j66CGA-3qxr-qr67-9983CGA-3x5j-gjpw-x2hrCGA-5gxc-q8hg-pg8hCGA-6cxp-x4v5-8hh8CGA-6qhh-xjfv-wf5gCGA-6x59-79w7-wfw3CGA-8mgq-jw89-6rpxCGA-c3p5-597j-vj3pCGA-crj5-x225-5363CGA-fj65-56qc-35v9CGA-fq4r-mxv2-vqj9CGA-fwmh-7j4f-2cc6CGA-h8vg-hhw7-r6hfCGA-pcfw-2fcw-4cxvCGA-pmpc-4vj8-7hpgCGA-prqw-6xj5-4q84CGA-q55h-vx3x-74rxCGA-q6vm-xg5h-cxcvCGA-q76r-682v-2j54CGA-q9x2-xg65-v49rCGA-qfh3-xmr3-92h4CGA-qr68-595r-3qq4CGA-r45w-jp5v-m7rvCGA-r733-7853-355qCGA-vj5v-gx94-mgg4CGA-w9c9-3c3f-7gmqCGA-x5m8-vmqq-gc29CGA-xph4-rg9h-xf52CGA-293v-gf8c-2ph4CGA-4567-j9p3-w9jjCGA-c43q-6xqc-c86vCGA-g3xf-f4fm-fh65CGA-p3xp-x2q6-r9vfCGA-6rpf-352g-fq3jCGA-8w8j-hjc7-4f7x
Awaiting Analysis
Published: 03 Aug 2026, 21:26
Last modified:04 Sept 2026, 21:20

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.7 HIGH
v4.0 (cve.org)
EPSS Score
0.25% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Aug 2026, 21:26
Published
Vulnerability first disclosed
04 Sept 2026, 21:20
Last Modified
Vulnerability information updated

Description

python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Trends

Current EPSS score: 0.25% Percentile: 17%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardapache-beam-python-3.11-sdk

    < 2.75.0-r2

  • chainguardapache-beam-python-3.12-sdk

    < 2.75.0-r1

  • chainguardapache-beam-python-3.13-sdk

    < 2.75.0-r2

  • chainguardauthentik-2025.12

    all

  • chainguarddatadog-agent-7.75-core-integrations

    all

  • chainguarddatadog-agent-fips-7.75-core-integrations

    all

  • chainguarddbt-snowflake

    all

  • chainguardkserve-storage-controller

    all

  • chainguardmlflow

    < 3.16.0-r0

  • chainguardopenstack-glance-2025.1

    < 30.2.0_git20260616-r8

  • chainguardopenstack-glance-2025.2

    < 31.1.0_git20260708-r2

  • chainguardopenstack-glance-2026.1

    < 32.0.0_git20260805-r0

  • chainguardopenstack-nova-2025.1

    < 31.3.0_git20260717-r3

  • chainguardopenstack-nova-2025.2

    < 32.2.0_git20260715-r2

  • chainguardopenstack-nova-2026.1

    < 33.0.1_git20260727-r1

  • chainguardsuperset-6.0

    all

  • chainguardvllm-openai-cuda-12.9

    all | < 0.29.0-r3

  • chainguardvllm-openai-cuda-13.0

    all

  • wolfidatadog-agent-7.75-core-integrations

    all

  • wolfikserve-storage-controller

    all

  • wolfimlflow

    < 3.16.0-r0

  • wolfisuperset-6.0

    all

  • debianpython-cryptography

    all | all | all | all | < 49.0.0-1

  • ubuntupython-cryptography

    all | all | all | all | < 46.0.5-1ubuntu2.2

  • pycacryptography

    < 49.0.0 | ≥ 42.0.0, < 49.0.0

  • PyPIcryptography

    < 49.0.0 | ≥ 42.0.0, < 49.0.0

References (14)