CVE-2026-27459: pyOpenSSL DTLS cookie callback buffer overflow

Published Mar 16, 2026
·
Updated

If a user provided callback to setcookiegeneratecallback returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer.

Cookie values that are too long are now rejected.

Other sources

pyOpenSSL DTLS cookie callback buffer overflow

Microsoft

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to setcookiegeneratecallback returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

NVD

Affected Software

3 affected componentsFixes available
pip/pyopenssl>=22.0.0<26.0.0
26.0.0
Microsoft azl3 pyOpenSSL 24.2.1-1
pyopenssl pyopenssl>=22.0.0<26.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/pyopenssl to a version that resolves this vulnerability.

    Fixed in 26.0.0
  2. Upgrade

    Upgrade pyOpenSSL to a version that resolves this vulnerability.

    Fixed in 26.0.0

Event History

Mar 16, 2026
Advisory Published
via GitHub·04:22 PM
Data Sourced
via GitHub·04:22 PM
DescriptionWeaknessAffected Software
Mar 17, 2026
CVE Published
via MITRE·11:34 PM
Data Sourced
via MITRE·11:34 PM
DescriptionWeakness
Mar 18, 2026
Data Sourced
via Red Hat·12:02 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·12:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 19, 2026
Data Sourced
via Microsoft·08:04 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:04 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-27459?

CVE-2026-27459 has been rated as a medium severity vulnerability due to the potential for a buffer overflow.

2

How do I fix CVE-2026-27459?

To fix CVE-2026-27459, upgrade pyOpenSSL to version 26.0.0 or later.

3

What causes the CVE-2026-27459 vulnerability?

CVE-2026-27459 is caused by a user-provided callback that returns a cookie value greater than 256 bytes, leading to buffer overflow.

4

Which versions of pyOpenSSL are affected by CVE-2026-27459?

Affected versions of pyOpenSSL are those between 22.0.0 and 26.0.0, inclusive.

5

Is CVE-2026-27459 a remote code execution vulnerability?

CVE-2026-27459 does not lead to remote code execution but may allow denial-of-service through a buffer overflow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-27459 - pyOpenSSL DTLS cookie callback buffer overflow - SecAlerts