{"api_version":"v1","generated_at":"2026-10-07T01:20:00+00:00","product":{"cve_count":9,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-pyca-cryptography-8e0c67bba44d","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/cryptography","name":"cryptography","next_cursor":null,"observations":[{"affected":"cryptography: >= 42.0.0, < 49.0.0","affected_versions_present":true,"cve_id":"CVE-2026-69249","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-69249","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-09-04T21:20:32.666Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-69249","primary_source":"","published":"2026-08-03T21:26:45.826Z"},{"affected":"cryptography: < 49.0.0","affected_versions_present":true,"cve_id":"CVE-2026-69248","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-69248","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-09-02T13:26:35.057Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-69248","primary_source":"","published":"2026-08-03T21:21:43.710Z"},{"affected":">= 44.0.0, < 50.0.0","affected_versions_present":true,"cve_id":"CVE-2026-69247","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-69247","fixed":"For more information visit https://access.redhat.com/errata/RHSA-2026:70965","last_modified":"2026-08-04T14:09:24.615Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-69247","primary_source":"","published":"2026-08-03T21:16:32.047Z"},{"affected":"cryptography: >= 45.0.0, < 46.0.7","affected_versions_present":true,"cve_id":"CVE-2026-39892","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39892","fixed":"RHSA-2026:24761: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9","last_modified":"2026-09-10T12:04:47.954Z","patch_url":"https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq","primary_source":"","published":"2026-04-08T20:49:41.967Z"},{"affected":"< 46.0.6","affected_versions_present":true,"cve_id":"CVE-2026-34073","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34073","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-31T13:52:00.999Z","patch_url":"","primary_source":"","published":"2026-03-31T02:04:36.275Z"},{"affected":"cryptography: < 46.0.5","affected_versions_present":true,"cve_id":"CVE-2026-26007","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26007","fixed":"RHSA-2026:13512: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9","last_modified":"2026-09-16T12:04:21.492Z","patch_url":"https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c","primary_source":"","published":"2026-02-10T21:42:56.471Z"},{"affected":">= 38.0.0, < 42.0.4","affected_versions_present":true,"cve_id":"CVE-2024-26130","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-26130","fixed":"42.0.4","last_modified":"2024-08-14T20:01:52.628Z","patch_url":"https://github.com/pyca/cryptography/pull/10423","primary_source":"","published":"2024-02-21T16:28:18.632Z"},{"affected":">= 3.1, < 41.0.6","affected_versions_present":true,"cve_id":"CVE-2023-49083","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-49083","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-18T15:32:14.214Z","patch_url":"https://github.com/pyca/cryptography/pull/9926","primary_source":"","published":"2023-11-29T18:50:24.263Z"},{"affected":">=1.8, < 39.0.1","affected_versions_present":true,"cve_id":"CVE-2023-23931","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-23931","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T21:47:19.856Z","patch_url":"https://github.com/pyca/cryptography/pull/8230/commits/94a50a9731f35405f0357fa5f3b177d46a726ab3","primary_source":"","published":"2023-02-07T20:54:03.628Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"pyca"}}
