You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"impact_statement": "The image has no consumer outside the cryptography package that calls pkcs7_decrypt_der, pkcs7_decrypt_pem, or pkcs7_decrypt_smime, and it does not expose an attacker-controlled PKCS#7 EnvelopedData decryption service."
},
{
"vulnerability": {
"name": "CVE-2026-69249"
},
"products": [
{
"@id": "pkg:pypi/cryptography@48.0.1"
}
],
"status": "not_affected",
"justification": "vulnerable_code_not_present",
"impact_statement": "The GitHub Reviewed Advisory range for CVE-2026-69249 is cryptography <=48.0.0 and the first patched version is 49.0.0. This image installs exact cryptography 48.0.1, which is outside the affected range; any scanner record for this exact package and version is an out-of-range finding."