MODERATEPyPI →
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
Affected packages
- cryptography— before 49.0.0
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.18%
- EPSS percentile
- 8.3%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 8%.
Sources
- https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c
- https://github.com/pyca/cryptography/pull/14888
- https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2
- https://github.com/pyca/cryptography
Structured record: https://osv.dev/vulnerability/GHSA-m2h6-j472-rp4c
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta