
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39892 is a buffer overflow vulnerability in the cryptography Python package (by PyCA) that occurs when non-contiguous buffers are passed to APIs accepting Python buffer objects, such as Hash.update(). It affects versions 45.0.0 through 46.0.6 and was disclosed on April 8, 2026, with a fix released in version 46.0.7. The vulnerability has a CVSS v3.1 base score of 9.8 (Critical) per Red Hat's assessment, though the authoritative CVSS v4.0 score from the GitHub Advisory is 6.9 (Medium) (GitHub Advisory, Red Hat Bugzilla). Downstream products from IBM (Maximo Application Suite, Cloud Pak for Business Automation, QRadar EDR, Instana, Process Mining, Business Automation Workflow) and Red Hat (Ansible Automation Platform) are also affected (GitHub Advisory).
The root cause is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-131 (Incorrect Calculation of Buffer Size). When a non-contiguous buffer — such as a reversed memoryview slice (buf[::-1]) — is passed to a Python buffer-accepting API like Hash.update(), the library incorrectly calculates the buffer size and reads past the end of the allocated memory region on Python versions greater than 3.11 (GitHub Security Advisory, Openwall oss-sec). The vulnerability is exploitable over the network without authentication or user interaction, as an attacker can supply crafted input to any application that passes user-controlled data through the affected cryptographic APIs (GitHub Advisory).
Successful exploitation could result in reading past memory boundaries, potentially exposing sensitive data processed during cryptographic operations (confidentiality impact), application crashes causing denial of service (availability impact), or in more severe scenarios, arbitrary code execution if memory corruption is leveraged (integrity impact). The CVSS v4.0 assessment rates the direct availability impact as Low with no confidentiality or integrity impact on the vulnerable system, though the CVSS v3.1 score reflects a worst-case scenario of High across all three pillars. Applications using the cryptography library for hashing, encryption, or key operations — including enterprise platforms like IBM Maximo and Red Hat Ansible Automation Platform — are within the affected asset scope (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.042% (0.000420), placing it in a low-probability exploitation tier. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).
The primary remediation is to upgrade the cryptography Python package to version 46.0.7 or later, which fixes the non-contiguous buffer handling issue (Openwall oss-sec, GitHub Security Advisory). Organizations should audit all environments and applications using cryptography versions 45.0.0–46.0.6 and prioritize upgrading. IBM has released interim fixes for affected products including Process Mining, Maximo Application Suite, Cloud Pak for Business Automation, Business Automation Workflow, QRadar EDR, and Instana; Red Hat has addressed the issue in Ansible Automation Platform via RHSA-2026:24761 and RHSA-2026:24762 (Red Hat Bugzilla). No configuration-based workaround is available; upgrading is the only effective mitigation.
The vulnerability was announced by Paul Kehrer (reaperhulk) of PyCA on the Python-announce mailing list and forwarded to the oss-security list by Alan Coopersmith on April 8, 2026 (Openwall oss-sec). Red Hat classified the issue as high severity and tracked it via Bugzilla with 82 CC'd users, reflecting broad organizational interest across enterprise Linux and automation products (Red Hat Bugzilla). IBM issued multiple security bulletins for affected products throughout April–June 2026. The OpenSUSE community also noted the fix in their April 2026 Tumbleweed monthly update.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."