Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.2
CVE-2026-27459: pyOpenSSL DTLS Cookie Overflow Risk: Large Cookie Values Crash Application
GHSA-5pwr-322w-8jr4
CVE-2026-27459
GHSA-5pwr-322w-8jr4
CVE-2026-27459
CVE-2026-27459
Summary
A bug in pyOpenSSL could cause a crash if a server is given a very long cookie value. This has been fixed by pyOpenSSL's developers, so you should update to the latest version to stay safe.
What to do
- Update pyopenssl to version 26.0.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | pyopenssl | pyopenssl |
>= 22.0.0, <= 26.0.0 cpe:2.3:a:pyopenssl:pyopenssl:*:*:*:*:*:*:*:* |
| pip | – | pyopenssl |
>= 22.0.0, < 26.0.0 Fix: upgrade to 26.0.0
|
| – | pyca | pyopenssl | >= 22.0.0, < 26.0.0 |
Original title
pyOpenSSL DTLS cookie callback buffer overflow
Original description
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
ghsa CVSS4.0
7.2
Vulnerability type
CWE-120
Classic Buffer Overflow
- https://nvd.nist.gov/vuln/detail/CVE-2026-27459
- https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4
- https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd40...
- https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/...
- https://github.com/advisories/GHSA-5pwr-322w-8jr4
- https://github.com/pyca/pyopenssl Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27459... Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:10754
- https://access.redhat.com/errata/RHSA-2026:11856
- https://access.redhat.com/errata/RHSA-2026:11916
- https://access.redhat.com/errata/RHSA-2026:11996
- https://access.redhat.com/errata/RHSA-2026:13508
- https://access.redhat.com/errata/RHSA-2026:13512
- https://access.redhat.com/errata/RHSA-2026:13545
- https://access.redhat.com/errata/RHSA-2026:13553
- https://access.redhat.com/errata/RHSA-2026:14835
- https://access.redhat.com/errata/RHSA-2026:14873
- https://access.redhat.com/errata/RHSA-2026:14874
- https://access.redhat.com/errata/RHSA-2026:19375
- https://access.redhat.com/errata/RHSA-2026:21017
- https://access.redhat.com/errata/RHSA-2026:22465
- https://access.redhat.com/errata/RHSA-2026:24853
- https://access.redhat.com/errata/RHSA-2026:7224
- https://access.redhat.com/errata/RHSA-2026:8437
- https://access.redhat.com/security/cve/CVE-2026-27459
- https://bugzilla.redhat.com/show_bug.cgi?id=2448503
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27459.json
Published: 17 Mar 2026 · Updated: 20 Jul 2026 · First seen: 16 Mar 2026