HarborGuard / CVE
Back to search
HIGHCVE-2026-27459Published Modified CNA GitHub_M

CVE-2026-27459: pyOpenSSL DTLS cookie callback buffer overflow

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

Metrics

CVSS v4.0
7.2
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • pyca / pyopenssl
    >= 22.0.0, < 26.0.0
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U