Vulnerability DatabaseGHSA-jm77-qphf-c4w8

GHSA-jm77-qphf-c4w8
Python vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-jm77-qphf-c4w8) affects pyca/cryptography's wheels which include a statically linked copy of OpenSSL. The issue impacts versions 0.8 through 41.0.2, with the fix available in version 41.0.3, released on August 1, 2023. This security concern specifically affects users installing from wheels built by the cryptography project and distributed on PyPI (GitHub Advisory).

Technical details

The vulnerability stems from multiple security issues in the included OpenSSL versions. The issues include problems with AES-SIV implementation ignoring empty associated data entries (CVE-2023-2975) and excessive time spent checking DH keys and parameters (CVE-2023-3446, CVE-2023-3817). The severity is classified as Low, primarily affecting the OpenSSL components bundled with the cryptography package (OpenSSL Advisory, OpenSSL Advisory, OpenSSL Advisory).

Impact

The impact varies depending on the specific OpenSSL vulnerability, but includes potential denial of service through excessive time spent checking DH keys and parameters, and authentication issues with AES-SIV implementation where empty data entries might be ignored. The vulnerabilities primarily affect applications that use specific OpenSSL functions for checking DH keys or parameters (OpenSSL Advisory).

Mitigation and workarounds

Users should upgrade to cryptography version 41.0.3 or later, which includes OpenSSL 3.1.2 with all security fixes. For users building from source (sdist), they are responsible for upgrading their own copy of OpenSSL. The update also includes fixes for a performance regression in loading DH public keys and a memory leak in ChaCha20Poly1305 (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23949HIGH8.6
  • PythonPython
  • jaraco.context
NoYesJan 20, 2026
CVE-2026-22219HIGH8.3
  • PythonPython
  • chainlit
NoYesJan 20, 2026
CVE-2026-23842HIGH7.5
  • PythonPython
  • chatterbot
NoYesJan 19, 2026
CVE-2026-23877MEDIUM5.3
  • PythonPython
  • swingmusic
NoYesJan 19, 2026
CVE-2026-23833LOW1.7
  • PythonPython
  • esphome
NoYesJan 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management