Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80034.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-80034
Upstream
Published
2026-03-18T00:16:19Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-27459 affecting package pyOpenSSL for versions less than 24.2.1-2
Details

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to set_cookie_generate_callback returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

References

Affected packages

Azure Linux:3 / pyOpenSSL

Package

Name
pyOpenSSL
Purl
pkg:rpm/azure-linux/pyOpenSSL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.2.1-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80034.json"