The PyPI package cryptography has a vulnerability in versions below 44.0.1:
GHSA-79v4-65xg-pq4g
All users of this package with the gcp extra cannot upgrade their cryptography package due to the dependency on pyopenssl>=23.2.0,<24.3.0 which in turn requires cryptography>=41.0.5,<44