The Lab · 2026-03-28 08:26:59 · GitHub Issues
A critical vulnerability in the widely-used Python cryptography library has been patched, addressing a flaw that could allow attackers to bypass DNS name constraints during certificate validation. The security advisory, CVE-2026-34073, reveals that versions prior to 46.0.5 failed to properly validate the "peer name" pr...
The Lab · 2026-03-28 08:27:06 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, addressing a flaw that could undermine certificate validation in specific, non-standard configurations. The issue, tracked as CVE-2026-34073, was a bug where X.509 name constraints were not correctly applied to peer names...
The Lab · 2026-03-28 08:27:07 · GitHub Issues
An MLflow AutoML project for ambient temperature regression was found running with a critically outdated version of the `cryptography` library, exposing it to a recently disclosed security vulnerability. The project's dependency was pinned at version 41.0.0, a version released in 2023, while the current patched release...
The Lab · 2026-03-28 09:27:01 · GitHub Issues
A critical security vulnerability in the widely-used Python `cryptography` library allows attackers to bypass DNS name constraints, potentially enabling certificate impersonation and man-in-the-middle attacks. The flaw, tracked as CVE-2026-34073, stems from a failure to validate the "peer name" presented during certifi...
The Lab · 2026-03-28 19:27:01 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a flaw in how X.509 certificates are validated. The bug, tracked as CVE-2026-34073, could allow an attacker to bypass critical name constraints during certificate verification if the leaf certificate contains a w...
The Lab · 2026-03-28 19:27:02 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a flaw in X.509 certificate validation that could allow attackers to bypass critical name constraints. The bug, tracked as CVE-2026-34073, was present when a leaf certificate contained a wildcard DNS Subject Alte...
The Lab · 2026-03-28 21:27:03 · GitHub Issues
The widely-used Python cryptography library has patched a significant security vulnerability in its certificate verification logic. The flaw, tracked as CVE-2026-34073, could allow an attacker to bypass critical name constraints when a leaf certificate contains a wildcard DNS SAN, potentially enabling impersonation att...
The Lab · 2026-03-29 00:26:52 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a flaw in X.509 certificate verification that could allow attackers to bypass name constraints. The bug, tracked as CVE-2026-34073, was present when a leaf certificate contained a wildcard DNS SAN (Subject Altern...
The Lab · 2026-03-29 02:27:06 · GitHub Issues
The widely-used Python cryptography library has patched a critical security vulnerability in its X.509 certificate validation logic. The flaw, tracked as CVE-2026-34073, could allow an attacker to bypass critical name constraints when a leaf certificate contains a wildcard DNS SAN. This bypass occurs during peer name v...
The Lab · 2026-03-29 02:27:08 · GitHub Issues
A critical security vulnerability in the widely used Python cryptography library has been patched, exposing a flaw in X.509 certificate validation that could undermine trust in secure connections. The bug, tracked as CVE-2026-34073, was discovered in the library's handling of name constraints when a leaf certificate co...
The Lab · 2026-03-29 03:27:02 · GitHub Issues
A critical security update has been released for the widely-used Python cryptography library, addressing a vulnerability that could undermine certificate verification in specific, non-standard configurations. The patch, version 46.0.6, fixes a bug where name constraints were not correctly applied to peer names during v...
The Lab · 2026-03-29 03:27:05 · GitHub Issues
The widely-used Python cryptography library has patched a significant security vulnerability in its X.509 certificate validation logic. The flaw, tracked as CVE-2026-34073, could allow an attacker to bypass critical name constraints when a leaf certificate contains a wildcard DNS SAN. This bypass occurs during peer nam...
The Lab · 2026-03-29 04:26:57 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, forcing a mandatory update for any system using versions prior to 46.0.5. The flaw, tracked as CVE-2026-34073, resides in the library's handling of DNS name constraints during certificate validation. Specifically, the vul...
The Lab · 2026-03-29 04:26:58 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a flaw that could allow unauthorized certificate validation. The issue, tracked as CVE-2026-34073, was present in versions prior to 46.0.5. The core failure was in the validation of DNS name constraints, a fundam...
The Lab · 2026-03-29 09:27:01 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a fundamental flaw in how the software validates DNS name constraints. The vulnerability, tracked as CVE-2026-34073, allowed a malicious actor to bypass critical security checks. Specifically, the library only va...
The Lab · 2026-03-31 05:27:03 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a flaw that could allow unauthorized certificate validation. The issue, tracked as CVE-2026-34073, was present in versions prior to 46.0.5. The core failure was in the validation of DNS name constraints, which we...
The Lab · 2026-03-31 08:27:06 · GitHub Issues
A critical vulnerability in a foundational Python cryptography library has been patched, exposing a flaw that could allow attackers to bypass DNS name constraints during certificate validation. The security advisory, tracked as CVE-2026-34073, was issued for the `pyca/cryptography` package. The core failure was that th...
The Lab · 2026-03-31 16:27:22 · GitHub Issues
A critical security vulnerability in the widely used Python cryptography library has been disclosed, allowing for a bypass of DNS name constraints during certificate validation. The flaw, tracked as CVE-2026-34073, was present in all versions prior to 46.0.6. The core failure was that DNS name constraints were only val...
The Lab · 2026-03-31 19:27:18 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a flaw that could allow unauthorized certificate validation. The issue, tracked as CVE-2026-34073, resided in the library's handling of DNS name constraints. In versions prior to 46.0.5, these constraints were on...
The Lab · 2026-04-01 06:27:01 · GitHub Issues
A critical security vulnerability in the widely-used Python cryptography library has been patched, exposing a fundamental flaw in how the software validates DNS name constraints. The issue, tracked as CVE-2026-34073, resided in versions prior to 46.0.5. The core failure was that DNS name constraints were only validated...