CVE-2026-27459

Source
https://cve.org/CVERecord?id=CVE-2026-27459
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27459.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27459
Aliases
Downstream
AZL (1)
BELL (1)
CGA (83)
CLEANSTART (17)
CLSA (3)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (10)
OESA (4)
openSUSE (2)
RHSA (8)
ROOT (1)
SUSE (10)
UBUNTU (1)
Related
Published
2026-03-17T23:34:28Z
Modified
2026-09-12T03:30:23Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
pyOpenSSL DTLS cookie callback buffer overflow
Details

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to set_cookie_generate_callback returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-120"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27459.json"
}
References

Affected packages

Git / github.com/pyca/pyopenssl

Affected ranges

Type
GIT
Repo
https://github.com/pyca/pyopenssl
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:pyopenssl:pyopenssl:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "22.0.0"
        },
        {
            "fixed":  "26.0.0"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

22.*
22.0.0
22.1.0
23.*
23.0.0
23.1.0
23.2.0
23.3.0
24.*
24.0.0
24.1.0
24.2.0
24.2.1
24.3.0
25.*
25.0.0
25.1.0
25.2.0
25.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27459.json"