CVE-2026-27459
Severity CVSS v4.0:
HIGH
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
18/03/2026
Last modified:
25/03/2026
Description
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
Impact
Base Score 4.0
7.20
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pyopenssl:pyopenssl:*:*:*:*:*:*:*:* | 22.0.0 (including) | 26.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



