cryptography@42.0.6 vulnerabilities
cryptography is a package which provides cryptographic recipes and primitives to Python developers.
-
latest version
43.0.3
-
latest non vulnerable version
-
first published
11 years ago
-
latest version published
a month ago
-
licenses detected
- [41.0.0,)
Direct Vulnerabilities
Known vulnerabilities in the cryptography package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Type Confusion in the Note: Users that are building cryptography source ("sdist") are responsible for upgrading their copy of OpenSSL. How to fix Type Confusion? Upgrade |
[37.0.0,43.0.1)
|
Affected versions of this package are vulnerable to Uncontrolled Resource Consumption due to improper user input validation in the Note: OpenSSL does not call these functions on untrusted DSA keys, so only applications that directly call these functions may be vulnerable. Also vulnerable are the OpenSSL How to fix Uncontrolled Resource Consumption? Upgrade |
[0,42.0.8)
|