https://seclists.org/oss-sec/2026/q1/414: pyca/cryptography: CVE-2026-34073: X.509: bypass of name constraints on wildcard SANs with matching peer names
Published Mar 30, 2026
·Updated
Affected Software
1 affected component
pypi/cryptography<=46.0.5
Frequently Asked Questions
1
What is the severity of CVE-2026-34073?
The severity of CVE-2026-34073 is classified as low.
2
How do I fix CVE-2026-34073?
To fix CVE-2026-34073, upgrade the cryptography package to version 46.0.6 or higher.
3
Which versions of cryptography are affected by CVE-2026-34073?
Versions of the cryptography package up to 46.0.5 are affected by CVE-2026-34073.
4
What type of vulnerability is CVE-2026-34073?
CVE-2026-34073 is a weakness that allows a bypass of name constraints on wildcard Subject Alternative Names in X.509 certificates.
5
Is there an official advisory for CVE-2026-34073?
Yes, the official advisory for CVE-2026-34073 is available on the GitHub security advisories page for the cryptography project.