CVE-2023-49083

MEDIUM

cryptography - DoS

Title source: llm
STIX 2.1

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

Scores

CVSS v3 5.9
EPSS 0.0093
EPSS Percentile 76.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (2)
cryptography.io/cryptography 3.1 - 41.0.6
pypi/cryptography 3.1 - 41.0.6PyPI
Published Nov 29, 2023
Tracked Since Feb 18, 2026