Buffer overflow in pyopenssl - CVE-2026-27459
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists because the callback provided to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, causing pyOpenSSL to overflow an OpenSSL-provided buffer. A remote attacker can pass specially crafted data to the application, trigger a buffer overflow and execute arbitrary code on the target system.
Affected software
Fedora
rust-cryptoki-sys
rust-wycheproof
rust-cryptoki
rust-asn1
rust-asn1_derive
kryoptic
pyOpenSSL
python-cryptography
How to mitigate CVE-2026-27459
rust-cryptoki-sys - update to 0.5.0-2.fc43
rust-wycheproof - update to 0.6.0-1.fc43
rust-cryptoki - update to 0.12.0-2.fc43
rust-asn1 - update to 0.22.0-1.fc43
rust-asn1_derive - update to 0.22.0-1.fc43
kryoptic - update to 1.5.0-2.fc43
pyOpenSSL - update to 26.0.0-1.fc43
python-cryptography - update to 46.0.5-1.fc43
External References
- https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst
- https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408
- https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4
- https://access.redhat.com/errata/RHSA-2026:10754
- https://access.redhat.com/errata/RHSA-2026:11856
- https://access.redhat.com/errata/RHSA-2026:11916
- https://access.redhat.com/errata/RHSA-2026:11996
- https://access.redhat.com/errata/RHSA-2026:13508
- https://access.redhat.com/errata/RHSA-2026:13512
- https://access.redhat.com/errata/RHSA-2026:13545
- https://access.redhat.com/errata/RHSA-2026:13553
- https://access.redhat.com/errata/RHSA-2026:14835
- https://access.redhat.com/errata/RHSA-2026:14873
- https://access.redhat.com/errata/RHSA-2026:14874
- https://access.redhat.com/errata/RHSA-2026:19375
- https://access.redhat.com/errata/RHSA-2026:21017
- https://access.redhat.com/errata/RHSA-2026:22465
- https://access.redhat.com/errata/RHSA-2026:24853
- https://access.redhat.com/errata/RHSA-2026:48085
- https://access.redhat.com/errata/RHSA-2026:48758
- https://access.redhat.com/errata/RHSA-2026:7224
- https://access.redhat.com/errata/RHSA-2026:8437
- https://access.redhat.com/security/cve/CVE-2026-27459
- https://bugzilla.redhat.com/show_bug.cgi?id=2448503
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27459.json