Heap Corruption Vulnerability in pymonocypher by Jetperch
CVE-2026-53720

5.1MEDIUM

Key Information:

Vendor

Jetperch

Vendor
CVE Published:
3 September 2026

What is CVE-2026-53720?

Prior to version 4.0.2.8, pymonocypher's implementation of argon2i_32 lacks proper validation for the nb_blocks size. This oversight can lead to buffer overflows if the supplied buffer is not adequately sized according to the API contract. As a result, this vulnerability may allow attackers to overwrite adjacent memory, leading to potential heap corruption. Users are advised to upgrade to version 4.0.2.8 or later to mitigate this risk.

Affected Version(s)

pymonocypher < 4.0.2.8

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.