CVE-2026-27459Critical· 9.8▾ MidnightpyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL wou…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.7%
Last analysed / modified upstream
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to set_cookie_generate_callback returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
pyopenssl >= 22.0.0, < 26.0.0Upgrade past the affected range:
pyopenssl 26.0.0Affected packages:
pyopenssl >= 22.0.0, < 26.0.0Patched in:
pyopenssl 26.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-27448LowpyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
CVE-2026-65332Medium· 4.3This issue was addressed through improved state management
CVE-2026-65338Medium· 4.3The issue was addressed with improved memory handling
CVE-2026-65334Medium· 4.3A memory corruption issue was addressed with improved state management
CVE-2026-65335Medium· 4.3This issue was addressed through improved state management
CVE-2026-65341Medium· 5.4The issue was addressed with improved memory handling