pyopenssl
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting pyopensslpage 1 of 1
- CVE-2013-4314NONECVSS 0.0EG 0.0✓ Fixed in 0.13.12013-09-30
vulnerable: 0.10 ... 0.9 (8 versions)
The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers …
- CVE-2018-1000807HIGHCVSS 8.1EG 8.1✓ Fixed in 17.5.02018-10-08
vulnerable: 0.10 ... 17.4.0 (20 versions)
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execu…
- CVE-2018-1000808MEDIUMCVSS 5.9EG 5.9✓ Fixed in 17.5.02018-10-08
vulnerable: 0.10 ... 17.4.0 (20 versions)
Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is ex…
Check whether pyopenssl is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for pyopenssl CVEs against the assets you own.
Start Free Scan →