peter bassill · operator
$ cve CVE-2020-36242 JSON

CVE-2020-36242

9.1
CRITICAL · CVSS 3.1 · EPSS 6.7% (pctl 94)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS6.72% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploitnone known
Published2021-02-07
Last modified2026-06-17

Affected (3)

VendorProduct
cryptography.iocryptography
fedoraprojectfedora
oraclecommunications cloud native core network function cloud native environment

References

→ the Explorer  ·  watch your stack  ·  NVD