CVE-2026-27459
EUVD-2026-1267718.03.2026, 00:16
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pyopenssl | pyopenssl | 22.0.0 ≤ 𝑥 < 26.0.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Vulnerability Media Exposure