GHSA-m959-cc7f-wv43 · Severity: low · Ecosystem: pip — cryptography has incomplete DNS name constraint enforcement on peer names
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.
Conclusion & alert: CVE-2026-34073 is rated Low Risk (9/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.02%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-31 | — | 0.02% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 1.7 | 4.0 | LOW |
|
— | — | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
GHSA-m959-cc7f-wv43 · Severity: low · Ecosystem: pip — cryptography has incomplete DNS name constraint enforcement on peer names
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2026-34073: 1 source package rows (py3-cryptography); 22 state rows across 3 repos (3.23-main, edge-community, edge-main); fixed 2, open 20. | https://security.alpinelinux.org/vuln/CVE-2026-34073 |
debian
|
not yet assigned | CVE-2026-34073 not yet assigned priority: Debian including 1 source packages (python-cryptography), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 3, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2026-34073 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2026-34073 |
suse
|
medium | CVE-2026-34073 severity moderate: SUSE including 9 source package names (python-cryptography, python2-cryptography, …), 63 product×package rows across 42 product lines (Image SL-Micro, Image SL-Micro-Base-VMware, … (42 product lines)): Known Not Affected 41, Fixed 21, First Fixed 1. | https://www.suse.com/security/cve/CVE-2026-34073/ |
ubuntu
|
medium | CVE-2026-34073 medium priority: Ubuntu including 1 source packages (python-cryptography), 7 status rows across 7 suites (bionic, focal, jammy, noble, questing, upstream, xenial): not-affected 6, released 1. | https://ubuntu.com/security/CVE-2026-34073 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cryptography.io | cryptography | < 46.0.6 | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* |
| URL | Tags |
|---|---|
| https://github.com/pyca/cryptography/security/advisories/GHSA-m959-cc7f-wv43 | Vendor Advisory |