๐Ÿ” CVE Alert

CVE-2026-53720

UNKNOWN 0.0

pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap. This issue has been patched in version 4.0.2.8.

CWE CWE-122 CWE-787 CWE-1284
Vendor jetperch
Product pymonocypher
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for jetperch pymonocypher

Be the first to know when new unknown vulnerabilities affecting jetperch pymonocypher are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

jetperch / pymonocypher
< 4.0.2.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jetperch/pymonocypher/security/advisories/GHSA-8f95-v3jq-cj86 github.com: https://github.com/jetperch/pymonocypher/commit/90ff5b13b13b5673c372e188f482d8c172e6ab86 github.com: https://github.com/jetperch/pymonocypher/releases/tag/v4.0.2.8