pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small (CVE-2026-53720)
A heap buffer overflow vulnerability exists in pymonocypher's argon2i_32 function due to insufficient checking of the nb_blocks buffer size. If the buffer provided is too small, the function may write beyond its allocated memory, potentially corrupting the heap. This vulnerability is fixed in version 4.0.2.8 by verifying the buffer size before use. Users should upgrade to version 4.0.2.8 or later or ensure the nb_blocks buffer is correctly sized to mitigate the risk.
AI Analysis
Technical Summary
The pymonocypher library contains a heap buffer overflow vulnerability in its argon2i_32 implementation. The issue arises because the function does not properly check the size of the nb_blocks buffer before writing to it. If the buffer is smaller than expected, this can lead to out-of-bounds writes and heap corruption. This vulnerability is identified as CVE-2026-53720 and is addressed in pymonocypher version 4.0.2.8 by adding buffer size verification. Users of versions prior to 4.0.2.8 are affected.
Potential Impact
Exploitation of this vulnerability could result in heap corruption, which may lead to application crashes or potentially enable further exploitation depending on the context. The CVSS 4.0 vector indicates local attack vector with low complexity and no privileges or user interaction required, but with limited impact on confidentiality and availability. No known exploits are reported in the wild.
Mitigation Recommendations
A fix is available in pymonocypher version 4.0.2.8. Users should upgrade to version 4.0.2.8 or later to remediate this vulnerability. Alternatively, ensuring that the nb_blocks buffer is correctly sized before use can mitigate the risk. No additional vendor advisories indicate other mitigation steps.
pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small (CVE-2026-53720)
Description
A heap buffer overflow vulnerability exists in pymonocypher's argon2i_32 function due to insufficient checking of the nb_blocks buffer size. If the buffer provided is too small, the function may write beyond its allocated memory, potentially corrupting the heap. This vulnerability is fixed in version 4.0.2.8 by verifying the buffer size before use. Users should upgrade to version 4.0.2.8 or later or ensure the nb_blocks buffer is correctly sized to mitigate the risk.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The pymonocypher library contains a heap buffer overflow vulnerability in its argon2i_32 implementation. The issue arises because the function does not properly check the size of the nb_blocks buffer before writing to it. If the buffer is smaller than expected, this can lead to out-of-bounds writes and heap corruption. This vulnerability is identified as CVE-2026-53720 and is addressed in pymonocypher version 4.0.2.8 by adding buffer size verification. Users of versions prior to 4.0.2.8 are affected.
Potential Impact
Exploitation of this vulnerability could result in heap corruption, which may lead to application crashes or potentially enable further exploitation depending on the context. The CVSS 4.0 vector indicates local attack vector with low complexity and no privileges or user interaction required, but with limited impact on confidentiality and availability. No known exploits are reported in the wild.
Mitigation Recommendations
A fix is available in pymonocypher version 4.0.2.8. Users should upgrade to version 4.0.2.8 or later to remediate this vulnerability. Alternatively, ensuring that the nb_blocks buffer is correctly sized before use can mitigate the risk. No additional vendor advisories indicate other mitigation steps.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8f95-v3jq-cj86
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53720"]
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a50bac868715ace435892ae
Added to database: 07/10/2026, 09:26:32 UTC
Last enriched: 09/07/2026, 11:06:37 UTC
Last updated: 09/11/2026, 04:45:03 UTC
Views: 134
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.