Skip to content

Pysaml2 security vulnerability #1012

Description

@itsBrady

Our security scanner is flagging version cryptography==43.0.3

This comes from the latest version of pysaml2

pysaml2==7.5.4

We can't just bump cryptography to 44.0.1 in the req's because pyopenSSL (also a dependency of pysaml2) doesn't allow.

cryptography==43.0.3
# via
# pyopenssl
# pysaml2

pyopenssl==24.2.1
# via pysaml2

Can you release a patch bumping pyopenssl, and cryptography please.

Activity

  1. itsBrady commented on Dec 23, 2025

    @itsBrady
    Author
     PACKAGE      │ VULNERABILITY ID │ INSTALLED VERSION │ FIXED VERSION │ SEVERITY │ CVSS2 │ CVSS3 │ STATUS │
    ├──────────────┼──────────────────┼───────────────────┼───────────────┼──────────┼───────┼───────┼────────┤
    │ cryptography │ CVE-2024-12797   │ 43.0.3            │ 44.0.1        │ HIGH     │       │ 7.4   │ FAILED │
    
  2. mikicz commented on Jan 2, 2026

    @mikicz

    Ideally this would get addressed by #977

  3. itsBrady commented on Jan 5, 2026

    @itsBrady
    Author

    Is there any ideas on when/if that will be going out?

  4. itsBrady commented on Jan 5, 2026

    @itsBrady
    Author

    @c00kiemon5ter apologies if you are not the correct person to ask, but is this on the radar to patch?

  5. lstorme commented on Feb 3, 2026

    @lstorme

    following, and we should remove PyOpenSSL dependency

  6. spaceone commented on Apr 21, 2026

    @spaceone
    Contributor

    @c00kiemon5ter What are the plans for the several reported security issues. It looks a little bit like this project is unmaintained. There are many requests for them to be addressed. A statement from you would be good.

  7. spaceone commented on Apr 21, 2026

    @spaceone
    Contributor

    This is the same issue as #1024

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions