---
id: CVE-2026-27459
title: pyOpenSSL is a Python wrapper around the OpenSSL library
summary: >-
  pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version
  22.0.0 and prior to version 26.0.0, if a user provided callback to
  `set_cookie_generate_callback` returned a cookie value greater than 256 bytes,
  pyOpenSSL wou…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: pyopenssl
product: pyopenssl
affected:
  - 'pyopenssl >= 22.0.0, < 26.0.0'
patched:
  - pyopenssl 26.0.0
published: '2026-03-18'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:17:59.900'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27459'
references:
  - url: >-
      https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst
    label: security-advisories@github.com
  - url: >-
      https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408
    label: security-advisories@github.com
  - url: 'https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4'
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:10754'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11856'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11916'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11996'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13508'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13512'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13545'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13553'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14835'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14873'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:14874'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19375'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21017'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22465'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24853'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:48085'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:48758'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:59153'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:7224'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8437'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-27459'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2448503'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27459.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-27459'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27459'
  - url: 'https://github.com/pyca/pyopenssl'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68780'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - score-dispute
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-03-18T19:52:08.536876Z'
scores:
  nvd: 9.8
  cna: 7.2
  vendor: 8.1
epss: 0.00882
epssPercentile: 0.57432
ingestedAt: '2026-07-01T15:50:58.722Z'
aliases:
  - GHSA-5pwr-322w-8jr4
  - PYSEC-2026-2269
ecosystem: pip
---

## Overview

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

## Affected

- `pyopenssl >= 22.0.0, < 26.0.0`

## Remediation

Upgrade past the affected range:

- `pyopenssl 26.0.0`

## Vendor advisories

- **RHSA-2026:13512** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13512)
- **RHSA-2026:10754** · Red Hat · fixed in: RHUI 4 for RHEL 8 · released 2026-04-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:10754)
- **RHSA-2026:14874** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:14874)
- **RHSA-2026:13508** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13508)
- **RHSA-2026:14873** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:14873)
- **RHSA-2026:14835** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:14835)
- **RHSA-2026:13553** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13553)
- **RHSA-2026:13545** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13545)
- **RHSA-2026:59153** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-08-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:59153)
- **RHSA-2026:48758** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:48758)
- **RHSA-2026:7224** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-04-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:7224)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat Update Infrastructure 4 for Cloud Providers, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27459.json)

## Package advisory (CVE-2026-27459)

Affected packages:

- `pyopenssl >= 22.0.0, < 26.0.0`

Patched in:

- `pyopenssl 26.0.0`

Source: https://osv.dev/vulnerability/GHSA-5pwr-322w-8jr4
