CVE-2026-27459: Pyopenssl

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

Affected products

  • Pyopenssl Pyopenssl: from 22.0.0, before 26.0.0 (fixed in 26.0.0)

Published 2026-03-18. Last modified 2026-09-10.