CVE-2026-34073
published 2026-03-31CVE-2026-34073: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.15%
5.0th percentile
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cryptography.io | cryptography | < 46.0.6 | 46.0.6 |
| cryptography.io | cryptography | >= 0 < 46.0.6 | 46.0.6 |
| debian | python-cryptography | < python-cryptography 46.0.6-1 (forky) | python-cryptography 46.0.6-1 (forky) |
| pyca | cryptography | < 46.0.6 | 46.0.6 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv4.01.7LOWCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian1.7LOW
vendor_redhat1.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-34073: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
osv·2026-03-31·CVSS 1.7
CVE-2026-34073 [LOW] CVE-2026-34073: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.
OSV
cryptography has incomplete DNS name constraint enforcement on peer names
osv·2026-03-27·CVSS 6.5
CVE-2026-34073 [MEDIUM] cryptography has incomplete DNS name constraint enforcement on peer names
cryptography has incomplete DNS name constraint enforcement on peer names
## Summary
In versions of cryptography prior to 46.0.5, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named `bar.example.com` to validate against a wildcard leaf certificate for `*.example.com`, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for `bar.example.com`.
This behavior resulted from a gap between RFC 5280 (which defines Name Constraint semantics) and RFC 9525 (which defines service identity semantics): put together, neither states definitively whether Name Constraints should be applied to peer names. To close this gap, crypt
GHSA
cryptography has incomplete DNS name constraint enforcement on peer names
ghsa·2026-03-27·CVSS 6.5
CVE-2026-34073 [MEDIUM] CWE-295 cryptography has incomplete DNS name constraint enforcement on peer names
cryptography has incomplete DNS name constraint enforcement on peer names
## Summary
In versions of cryptography prior to 46.0.5, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named `bar.example.com` to validate against a wildcard leaf certificate for `*.example.com`, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for `bar.example.com`.
This behavior resulted from a gap between RFC 5280 (which defines Name Constraint semantics) and RFC 9525 (which defines service identity semantics): put together, neither states definitively whether Name Constraints should be applied to peer names. To close this gap, crypt
Red Hat
cryptography: python: Cryptography: Security bypass due to improper DNS name constraint validation
vendor_redhat·2026-03-31·CVSS 1.7
CVE-2026-34073 [LOW] CWE-295 cryptography: python: Cryptography: Security bypass due to improper DNS name constraint validation
cryptography: python: Cryptography: Security bypass due to improper DNS name constraint validation
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.
A flaw was found in the `cryptography` library. This vulnerability occurs because DNS (Domain Name System) name constraints were not pro
Debian
CVE-2026-34073: python-cryptography - cryptography is a package designed to expose cryptographic primitives and recipe...
vendor_debian·2026·CVSS 1.7
CVE-2026-34073 [LOW] CVE-2026-34073: python-cryptography - cryptography is a package designed to expose cryptographic primitives and recipe...
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 46.0.6-1)
sid: resolved (fixed in 46.0.6-1)
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-32983 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2026-32983 [MEDIUM] CVE-2026-32983 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32983 :
Wazuh Server vulnerability analysis and mitigation
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.
Source : NVD
## 6.9
Score
Published March 27, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Wazuh Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 34.5
Exploitation Probability (EPSS) 0.1
Affected packages and libr
Wiz
CVE-2025-15615 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2025-15615 [MEDIUM] CVE-2025-15615 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15615 :
Wazuh Server vulnerability analysis and mitigation
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.
Source : NVD
## 6.9
Score
Published March 27, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Wazuh Server
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 36.3
Exploitation Probability (EPSS) 0.2
Affected packages and lib
Wiz
CVE-2025-15612 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2025-15612 [MEDIUM] CVE-2025-15612 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15612 :
Wazuh Server vulnerability analysis and mitigation
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify downloaded dependencies or code during the build process, leading to remote code execution and supply chain compromise.
Source : NVD
## 6.3
Score
Published March 27, 2026
Severity MEDIUM
CNA Score 6.3
Affected Technologies
Wazuh Server
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15
Exploitation Probability (EPSS) N/A
Affected packages and lib
Wiz
CVE-2026-34073 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 1.7
CVE-2026-34073 [LOW] CVE-2026-34073 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34073 :
Python vulnerability analysis and mitigation
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.
Source : NVD
## 1.7
Score
Published March 31, 2026
Severity LOW
CNA Score 1.7
Affected Technologies
Python
Mitmproxy
Has Public Exploit No
Has CISA KEV Explo
Wiz
CVE-2025-15616 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2025-15616 [MEDIUM] CVE-2025-15616 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15616 :
Wazuh Server vulnerability analysis and mitigation
Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags, and Kaspersky AR script parameters. Attackers can exploit these vulnerabilities by injecting malicious commands through configuration files, SMTP server settings, and custom flags to achieve remote code execution on affected systems.
Source : NVD
## 7.1
Score
Published March 27, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
Wazuh Server
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due
Wiz
CVE-2025-15617 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.9
CVE-2025-15617 [MEDIUM] CVE-2025-15617 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15617 :
Wazuh Server vulnerability analysis and mitigation
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as pushing malicious commits or altering release tags.
Source : NVD
## 8.3
Score
Published March 27, 2026
Severity HIGH
CNA Score 8.3
Affected Technologies
Wazuh Server
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:wazuh:wazuh
Sources
Linux Severity HIGH Has Fix A
Bugzilla
CVE-2026-34073 python-cryptography: Cryptography: Security bypass due to improper DNS name constraint validation
bugzilla·2026-03-31·CVSS 1.7
CVE-2026-34073 [LOW] CVE-2026-34073 python-cryptography: Cryptography: Security bypass due to improper DNS name constraint validation
CVE-2026-34073 python-cryptography: Cryptography: Security bypass due to improper DNS name constraint validation
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version 46.0.6, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named bar.example.com to validate against a wildcard leaf certificate for *.example.com, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for bar.example.com. This issue has been patched in version 46.0.6.
Bugzilla
CVE-2026-34073 pypy: Cryptography: Security bypass due to improper DNS name constraint validation [fedora-all]
bugzilla·2026-03-31·CVSS 1.7
CVE-2026-34073 [LOW] CVE-2026-34073 pypy: Cryptography: Security bypass due to improper DNS name constraint validation [fedora-all]
CVE-2026-34073 pypy: Cryptography: Security bypass due to improper DNS name constraint validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
The relevant code is not there in the bundled cryptograhy.
Bugzilla
CVE-2026-34073 pypy3.10: Cryptography: Security bypass due to improper DNS name constraint validation [fedora-all]
bugzilla·2026-03-31·CVSS 1.7
CVE-2026-34073 [LOW] CVE-2026-34073 pypy3.10: Cryptography: Security bypass due to improper DNS name constraint validation [fedora-all]
CVE-2026-34073 pypy3.10: Cryptography: Security bypass due to improper DNS name constraint validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
The cryptography directory is just a version stub, there is no python level code handling name constraints.
Bugzilla
CVE-2026-34073 pypy3.11: Cryptography: Security bypass due to improper DNS name constraint validation [fedora-all]
bugzilla·2026-03-31·CVSS 1.7
CVE-2026-34073 [LOW] CVE-2026-34073 pypy3.11: Cryptography: Security bypass due to improper DNS name constraint validation [fedora-all]
CVE-2026-34073 pypy3.11: Cryptography: Security bypass due to improper DNS name constraint validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
The cryptography directory is just a version stub, there is no python level code handling name constraints.
2026-03-31
Published