Logo
vulnerabilityCVE-2026-27459
Name
CVE-2026-27459
Source
NVD ( link)Debian ( link)
Description
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-pyopenssl
Patched

Vulnerability Ratings#


7.2
CVSSv4
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
26.3.0
Not Affected
yocto
scarthgap
24.0.0
Patched

Resolved with patches#


python3-pyopenssl (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix buffer overflow in DTLS cookie generation callback
Alex Gaynor <alex.gaynor@gmail.com>
CVE-2026-27459

python3-pyopenssl (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix buffer overflow in DTLS cookie generation callback
Alex Gaynor <alex.gaynor@gmail.com>
CVE-2026-27459