Improper Certificate Validation Affecting python3.14-cryptography package, versions *


Severity

Recommended
medium

Based on CentOS security rating.

Threat Intelligence

EPSS
0.19% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS10-PYTHON314CRYPTOGRAPHY-19398161
  • published28 Aug 2026
  • disclosed3 Aug 2026

Introduced: 3 Aug 2026

NewCVE-2026-69248  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

There is no fixed version for Centos:10 python3.14-cryptography.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.14-cryptography package and not the python3.14-cryptography package as distributed by Centos. See How to fix? for Centos:10 relevant fixed versions and status.

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.

CVSS Base Scores

version 3.1