Improper Certificate Validation Affecting cryptography package, versions [,46.0.6)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.15% (5th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-CRYPTOGRAPHY-15809188
  • published29 Mar 2026
  • disclosed27 Mar 2026
  • credit1seal

Introduced: 27 Mar 2026

CVE-2026-34073  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade cryptography to version 46.0.6 or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation through the NameChain DNS verification logic in src/rust/cryptography-x509-verification. An attacker can make a peer name, such as bar.example.com, validate against a wildcard leaf certificate like *.example.com even when an issuing certificate in the chain excludes that DNS subtree, causing improper certificate acceptance.

Notes

  • The flaw affects X.509 path validation when DNS name constraints are present, and the leaf certificate uses a wildcard DNS SAN.
  • The maintainers note that ordinary X.509 topologies, including those used by the Web PKI, are not affected, and exploitation requires an uncommon certificate hierarchy.

CVSS Base Scores

version 4.0
version 3.1