Generated remediation guidance and an executive summary. No account required.
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.
Use CWE-476, Cryptography.Io vendor hub and Cryptography product page to widen CVE-2023-49083 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-36242, CVE-2026-26007 and CVE-2024-26130 for nearby disclosures in the same product family.