CVE-2026-27459Patch(pyopenssl / pyopenssl)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch pyopenssl pyopenssl systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pyopenssl

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • General: 2 classified signals
  • Disposal: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-03-18); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
pyopenssl

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-19: 1Mentions · 2026-03-21: 1Mentions · 2026-03-24: 1Mentions · 2026-03-27: 1Mentions · 2026-06-04: 1Active Exploitation · 2026-03-24: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-06-04: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-21: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-27: 1Technical Details · 2026-06-04: 103-1803-1903-2103-2403-2706-04
Signal classification4 categories
Patch
342.9%
General
228.6%
Disposal
114.3%
Active Exploitation
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-182
Disposal1General1
2026-03-191
General1
2026-03-211
Patch1
2026-03-241
Active Exploitation1
2026-03-271
Patch1
2026-06-041
Patch1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Patch

    2 CVEs fixed in pyOpenSSL 26.0.0 https://www.openwall.com/lists/oss-security/2026/03/20/5 CVE-2026-27459: Buffer overflow if a DTLS cookie callback returned a cookie longer than DTLS1_COOKIE_LENGTH bytes CVE-2026-27448: set_tlsext_servername_callback exceptions were silently swallowed and handshake would proceed

    Post summary

    The post announces that CVE‑2026‑27459 and CVE‑2026‑27448 have been fixed in pyOpenSSL 26.0.0, provides technical details of the flaws, and does not mention exploits or active use.

    02072654
    4.4K followersView on X
  • اپیک‌تر از همیشه@IranRevolt2026
    Active Exploitation

    نگه میدارن و به گا میرن. به زیبایی. همین هفته پیش برای لایبرری پایتون openssl یه آسیب‌پذیری جدی پیدا شد که مطمئنم از هر دوتا سرور تحت پایتون یکی اسیرشه https://www.sentinelone.com/vulnerability-database/cve-2026-27459/

    Post summary

    The post announces a serious CVE-2026-27459 in Python's OpenSSL library and suggests it is currently being exploited, though no PoC, exploit code, patch, or debunking is referenced.

    00010142
    163 followersView on X
  • ThreatCluster@threatcluster
    Patch

    SUSE fixed three vulnerabilities in Multi-Linux Manager, including CVE-2026-31958 in Tornado causing denial of service and CVE-2026-27459 in pyOpenSSL triggering buffer overflow, according to SUSE advisories published 3 June 2026. https://threatcluster.io/cluster/critical-vulnerabilities-in-suse-multi-linux-manager-affecti-55490848

    Post summary

    SUSE has released fixes for CVE-2026-31958 and CVE-2026-27459, addressing a denial‑of‑service in Tornado and a buffer overflow in pyOpenSSL, with advisories issued on June 3, 2026.

    0000079
    289 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical DTLS cookie callback bug CVE-2026-27459 in pyOpenSSL patched in v26.0.0 with python-cryptography 46.0.5, Fedora 43 and CentOS 8 users urged to update via dnf. https://threatcluster.io/cluster/critical-buffer-overflow-vulnerability-in-pyopenssl-requires-a586876c

    Post summary

    The post announces the CVE‑2026‑27459 patch for pyOpenSSL, urges updates, and gives specific version information but does not include PoC or exploitation details.

    0000040
    128 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-27459 📊 Severity: 7.2 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-27459 #CVE-2026-27459 #CVE #High  #CyberSecurity #InfoSec https://t.co/Jjt5odijkn

    Post summary

    The tweet merely announces CVE-2026-27459 with its severity score, offering no further technical details or remediation guidance.

    0000037
    104 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27459 pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_… https://www.cve.org/CVERecord?id=CVE-2026-27459

    Post summary

    The text references CVE-2026-27459 in pyOpenSSL, noting affected versions and a callback issue, but provides no evidence of exploitation, patches, or PoC.

    00000117
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disposal

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-27459 - pyOpenSSL DTLS cookie callback buffer overflow Intel Report: https://ift.tt/v0x1G5q

    Post summary

    A new CVE, CVE-2026-27459, involving a buffer overflow in pyOpenSSL's DTLS cookie callback function has been reported.

    0000037
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppyopensslpyopenssl---

Explore more