CVE-2026-34073
MediumAdvisory
Published 27 Mar 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.002
- 5th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 610
- of 17,787 indexed, latest versions
- Container images
- 498
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
cryptography has incomplete DNS name constraint enforcement on peer names
Carried by container images the latest versions of 610 of 17,787 indexed charts deploy, on 498 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| cryptographypypi | 1.7.2, 1.9, 2.1.4, 2.2.2+69 more | 46.0.6 | 498 |
| python-cryptographydeb | 38.0.4-3, 38.0.4-3+deb12u1, 43.0.0-3+deb13u1 | no fix listed | 14 |
| py3-cryptographyapk | 46.0.5-r0 | 46.0.7-r0 | 1 |
- OSV records
- ALPINE-CVE-2026-34073DEBIAN-CVE-2026-34073GHSA-m959-cc7f-wv43
- Also known as
- PYSEC-2026-35
Charts affected
610 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| wazuhwazuh-helm-eksVerified publisher | 1.2.10 | 1 of 6See more | 5,484 |
| wazuh-manager-filebeatwazuh-manager-filebeat | 0.1.0-gamma | 1 of 1See more | 11,167 |
| supersetwbstack | 0.1.0 | 1 of 1See more | 6,540 |
| juicefs-csi-driverwenerme | 0.32.5 | 1 of 5See more | 8,824 |
| ceph-csi-cephfswikimedia | 0.1.8 | 1 of 5See more | 10,286 |
| ceph-csi-rbdwikimedia | 0.1.13 | 1 of 6See more | 11,785 |
| powerdnsadminwitcom-gmbh | 0.3.4 | 1 of 1See more | 2,643 |
| zerossl-cert-managerzerossl-cert-manager | 0.1.0 | 1 of 2See more | 569 |
| alertmanager-matrix-forwarderzloi-space | 1.0.1 | 1 of 2See more | 3,118 |
| grafana-matrix-forwarderzloi-space | 1.0.0 | 1 of 2See more | 1,636 |
Container images carrying it
498 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.