CVE-2026-27459 PUBLISHED CVSS 7.400000095367432 HIGH

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

EPSS 0.02% · 5.2th percentile

Risk Scores

CVSS v3.1
7.400000095367432
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.02%
5.2th percentile

Affected Products

VendorProductVersions
pyopensslpyopenssl22.0.0
PyPIpyopenssl22.0.0
libexif_projectlibexif
libexif projectlibexif0
linuxlinux_kernel2.6.24, 2.6.24, 2.6.24
LinuxLinux6.12.75, 6.18.14, 6.19.4

Timeline

References

…and 15 more

Open in Interactive Console →