CVE-2026-53720
pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap. This issue has been patched in version 4.0.2.8.
| CWE | CWE-122 CWE-787 CWE-1284 |
| Vendor | jetperch |
| Product | pymonocypher |
| Published | Sep 3, 2026 |
| Last Updated | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for jetperch pymonocypher
Be the first to know when new unknown vulnerabilities affecting jetperch pymonocypher are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
jetperch / pymonocypher
< 4.0.2.8