Name
python3-pyopenssl
Version
22.0.0
Type
library
Description
Simple Python wrapper around the OpenSSL library
Licenses
Apache-2.0
PURL
-
CPE
cpe:2.3:*:*:python3-pyopenssl:22.0.0:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
Handle exceptions in set_tlsext_servername_callback callbacks
Alex Gaynor <alex.gaynor@gmail.com>
CVE-2026-27448
2
Fix buffer overflow in DTLS cookie generation callback
Alex Gaynor <alex.gaynor@gmail.com>
CVE-2026-27459
Vulnerabilities#
Name
Analysis
Description
Patched
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
Patched
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.