
2 CVEs fixed in pyOpenSSL 26.0.0 https://www.openwall.com/lists/oss-security/2026/03/20/5 CVE-2026-27459: Buffer overflow if a DTLS cookie callback returned a cookie longer than DTLS1_COOKIE_LENGTH bytes CVE-2026-27448: set_tlsext_servername_callback exceptions were silently swallowed and handshake would proceed
Post summary
The note announces that CVE-2026-27459 and CVE-2026-27448 have been fixed in pyOpenSSL 26.0.0, providing brief technical details of the issues.



