{"id":"CVE-2026-27459","title":"pyOpenSSL is a Python wrapper around the OpenSSL library","summary":"pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL wou…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-120"],"vendor":"pyopenssl","product":"pyopenssl","affected":["pyopenssl >= 22.0.0, < 26.0.0"],"patched":["pyopenssl 26.0.0"],"published":"2026-03-18","updated":"2026-09-10","sourceUpdated":"2026-09-10T13:17:59.900","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-27459","references":[{"url":"https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst","label":"security-advisories@github.com"},{"url":"https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408","label":"security-advisories@github.com"},{"url":"https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4","label":"security-advisories@github.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:10754","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11856","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11916","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:11996","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13508","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13512","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13545","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:13553","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14835","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14873","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:14874","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:21017","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22465","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:24853","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:48085","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:48758","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:59153","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:7224","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:8437","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-27459","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2448503","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27459.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-27459"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27459"},{"url":"https://github.com/pyca/pyopenssl"},{"url":"https://access.redhat.com/errata/RHSA-2026:68780"}],"tags":["nvd","cve.org","csaf","vex","red-hat","osv","pip","score-dispute"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-03-18T19:52:08.536876Z"},"scores":{"nvd":9.8,"cna":7.2,"vendor":8.1},"epss":0.00704,"epssPercentile":0.51886,"ingestedAt":"2026-07-01T15:50:58.722Z","aliases":["GHSA-5pwr-322w-8jr4","PYSEC-2026-2269"],"ecosystem":"pip","slug":"CVE-2026-27459","body":"## Overview\n\npyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.\n\n## Affected\n\n- `pyopenssl >= 22.0.0, < 26.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `pyopenssl 26.0.0`\n\n## Vendor advisories\n\n- **RHSA-2026:13512** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13512)\n- **RHSA-2026:10754** · Red Hat · fixed in: RHUI 4 for RHEL 8 · released 2026-04-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:10754)\n- **RHSA-2026:14874** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:14874)\n- **RHSA-2026:13508** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13508)\n- **RHSA-2026:14873** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:14873)\n- **RHSA-2026:14835** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:14835)\n- **RHSA-2026:13553** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13553)\n- **RHSA-2026:13545** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13545)\n- **RHSA-2026:59153** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59153)\n- **RHSA-2026:48758** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48758)\n- **RHSA-2026:7224** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-04-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:7224)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27459.json)\n\n## Package advisory (CVE-2026-27459)\n\nAffected packages:\n\n- `pyopenssl >= 22.0.0, < 26.0.0`\n\nPatched in:\n\n- `pyopenssl 26.0.0`\n\nSource: https://osv.dev/vulnerability/GHSA-5pwr-322w-8jr4","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}