CVE-2026-27448
EUVD-2026-1267518.03.2026, 00:16
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pyopenssl | pyopenssl | 0.14 ≤ 𝑥 < 26.0.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Vulnerability Media Exposure