Logo
vulnerabilityCVE-2026-27448
Name
CVE-2026-27448
Source
NVD ( link)Debian ( link)
Description
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-pyopenssl
Patched

Vulnerability Ratings#


1.7
CVSSv4
5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
26.3.0
Not Affected
yocto
scarthgap
24.0.0
Patched

Resolved with patches#


python3-pyopenssl (yocto:kirkstone)

#
Title
Author
Resolve
1
Handle exceptions in set_tlsext_servername_callback callbacks
Alex Gaynor <alex.gaynor@gmail.com>
CVE-2026-27448

python3-pyopenssl (yocto:scarthgap)

#
Title
Author
Resolve
1
Handle exceptions in set_tlsext_servername_callback callbacks
Alex Gaynor <alex.gaynor@gmail.com>
CVE-2026-27448