<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:18:17 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:15608 — Important: python3.12-cryptography security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:15608</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.12-cryptography&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override (CVE-2024-26130)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.12-cryptography&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override (CVE-2024-26130)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:15608</guid>
    </item>
    <item>
      <title>bdu:2024-03237</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-03237</link>
      <description>bdu:2024-03237</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-03237</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-26130</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-26130</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-cryptography, Alpaquita:stream: py3-cryptography&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-cryptography, Alpaquita:stream: py3-cryptography&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-26130</guid>
    </item>
    <item>
      <title>BREW-azure-cli-CVE-2024-26130 — cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certif…</title>
      <link>https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2024-26130</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: azure-cli&lt;/p&gt;
&lt;p&gt;If `pkcs12.serialize_key_and_certificates` is called with both:&lt;/p&gt;
&lt;p&gt;1. A certificate whose public key did not match the provided private key
2. An `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`&lt;/p&gt;
&lt;p&gt;Then a NULL pointer dereference would occur, crashing the Python process.&lt;/p&gt;
&lt;p&gt;This has been resolved, and now a `ValueError` is properly raised.&lt;/p&gt;
&lt;p&gt;Patched in https://github.com/pyca/cryptography/pull/10423&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: azure-cli&lt;/p&gt;
&lt;p&gt;If `pkcs12.serialize_key_and_certificates` is called with both:&lt;/p&gt;
&lt;p&gt;1. A certificate whose public key did not match the provided private key
2. An `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`&lt;/p&gt;
&lt;p&gt;Then a NULL pointer dereference would occur, crashing the Python process.&lt;/p&gt;
&lt;p&gt;This has been resolved, and now a `ValueError` is properly raised.&lt;/p&gt;
&lt;p&gt;Patched in https://github.com/pyca/cryptography/pull/10423&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-azure-cli-cve-2024-26130</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0305 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0305</link>
      <description>certfr-2024-avi-0305</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0305</guid>
    </item>
    <item>
      <title>EUVD-2026-158618</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-158618</link>
      <description>EUVD-2026-158618</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-158618</guid>
    </item>
    <item>
      <title>fkie_cve-2024-26130</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26130</link>
      <description>&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-26130</guid>
    </item>
    <item>
      <title>GHSA-6vqw-3v5j-54x4 — cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certif…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6vqw-3v5j-54x4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cryptography&lt;/p&gt;
&lt;p&gt;If `pkcs12.serialize_key_and_certificates` is called with both:&lt;/p&gt;
&lt;p&gt;1. A certificate whose public key did not match the provided private key
2. An `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`&lt;/p&gt;
&lt;p&gt;Then a NULL pointer dereference would occur, crashing the Python process.&lt;/p&gt;
&lt;p&gt;This has been resolved, and now a `ValueError` is properly raised.&lt;/p&gt;
&lt;p&gt;Patched in https://github.com/pyca/cryptography/pull/10423&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cryptography&lt;/p&gt;
&lt;p&gt;If `pkcs12.serialize_key_and_certificates` is called with both:&lt;/p&gt;
&lt;p&gt;1. A certificate whose public key did not match the provided private key
2. An `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`&lt;/p&gt;
&lt;p&gt;Then a NULL pointer dereference would occur, crashing the Python process.&lt;/p&gt;
&lt;p&gt;This has been resolved, and now a `ValueError` is properly raised.&lt;/p&gt;
&lt;p&gt;Patched in https://github.com/pyca/cryptography/pull/10423&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6vqw-3v5j-54x4</guid>
    </item>
    <item>
      <title>gsd-2024-26130</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-26130</link>
      <description>gsd-2024-26130</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-26130</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13710-1 — python310-cryptography-42.0.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13710-1</link>
      <description>&lt;p&gt;python310-cryptography-42.0.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-cryptography-42.0.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13710-1</guid>
    </item>
    <item>
      <title>PYSEC-2024-225</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-225</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-225</guid>
    </item>
    <item>
      <title>RHSA-2024:3781 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3781</link>
      <description>&lt;p&gt;pip: Mercurial configuration injectable in repo revision when installing via pip golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm python-cryptography: NULL-dereference when loading PKCS7 certificates pillow: Arbitrary Code Execution via the environment parameter python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headers python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode() python-pydantic: regular expression denial of service via crafted email string sqlparse: parsing heavily nested list leads to denial of service psf/black: ReDoS via the lines_with_leading_tabs_expanded() function in strings.py file golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override aiohttp: XSS on index pages for static file handling python-django: Potential regular expression denial-of-service in django.utils.text.Truncator.words() python-pillow: buffer overflow in _imagingcms.c follow-redirects: Possible credential leak aiohttp: DoS when trying to parse malformed POST requests python-social-auth: Improper Handling of Case Sensitivity in social-auth-app-django jinja2: accept…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pip: Mercurial configuration injectable in repo revision when installing via pip golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm python-cryptography: NULL-dereference when loading PKCS7 certificates pillow: Arbitrary Code Execution via the environment parameter python-gunicorn: HTTP Request Smuggling due to improper validation of Transfer-Encoding headers python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode() python-pydantic: regular expression denial of service via crafted email string sqlparse: parsing heavily nested list leads to denial of service psf/black: ReDoS via the lines_with_leading_tabs_expanded() function in strings.py file golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override aiohttp: XSS on index pages for static file handling python-django: Potential regular expression denial-of-service in django.utils.text.Truncator.words() python-pillow: buffer overflow in _imagingcms.c follow-redirects: Possible credential leak aiohttp: DoS when trying to parse malformed POST requests python-social-auth: Improper Handling of Case Sensitivity in social-auth-app-django jinja2: accept…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3781</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0763-1 — Security update for python-cryptography</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0763-1</link>
      <description>&lt;p&gt;Security update for python-cryptography&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-cryptography&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0763-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-26130</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26130</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: python-cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: python-cryptography&lt;/p&gt;
&lt;p&gt;cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`, then a NULL pointer dereference would occur, crashing the Python process. This has been resolved in version 42.0.4, the first version in which a `ValueError` is properly raised.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26130</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0869 — Oracle Communications: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0869</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0869</guid>
    </item>
  </channel>
</rss>
