{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3oredhatenterprise_linux/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*","cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-26130"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Enterprise Linux (python-cryptography)","Enterprise Linux"],"_cs_severities":["low"],"_cs_tags":["vulnerability","linux","cryptography","low-severity"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eThe python-cryptography library included in Red Hat Enterprise Linux (RHEL) is affected by multiple security vulnerabilities, most notably CVE-2024-26130. These flaws stem from improper handling of specific cryptographic operations within the library. A remote, unauthenticated attacker could leverage these weaknesses to bypass security restrictions or trigger a denial-of-service (DoS) condition, potentially leading to application crashes or the compromise of integrity in services relying on affected cryptographic functions. Defenders should prioritize updating the python-cryptography package across all RHEL distributions, as it is a foundational library for many Python-based services and management utilities.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could lead to a denial-of-service, rendering impacted services unavailable, or the subversion of cryptographic protections intended to secure data in transit or at rest. All RHEL environments utilizing the affected library are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of systems running the affected python-cryptography versions. Use package management tools to audit installed versions and ensure the latest security updates provided by Red Hat are applied.\u003c/p\u003e\n","date_modified":"2026-09-11T12:54:16Z","date_published":"2026-09-08T13:37:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rhel-python-cryptography/","summary":"Multiple vulnerabilities in the python-cryptography package for Red Hat Enterprise Linux, including CVE-2024-26130, may allow a remote, unauthenticated attacker to bypass security controls or cause a denial-of-service condition.","title":"Multiple Vulnerabilities in Red Hat Enterprise Linux python-cryptography Package","url":"https://feed.craftedsignal.io/briefs/2026-09-rhel-python-cryptography/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}