CVE-2026-27459

CRITICAL

pyOpenSSL DTLS cookie callback buffer overflow

Title source: cna
STIX 2.1

Description

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

Scores

CVSS v3 9.8
EPSS 0.0003
EPSS Percentile 7.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (3)
pyca/pyopenssl >= 22.0.0, < 26.0.0
pyopenssl/pyopenssl 22.0.0 - 26.0.0
pypi/pyopenssl 22.0.0 - 26.0.0PyPI
Published Mar 18, 2026
Tracked Since Mar 18, 2026