216.73.216.226

CVE-2026-27448

· Published 18/03/2026 00:16 · Modified 18/03/2026 14:52

Labels: CVE-2026-27448 2026-03-18CVE-2026-27448CWE-636[email protected]

Essential information

Published
18/03/2026 00:16
Modified
18/03/2026 14:52
Author
Creator
CVSS
1.7 LOW (v3) 1.7 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pyopenssl / pyopenssl cpe:2.3:a:pyopenssl:pyopenssl:0.14.0-25.9999:*:*:*:*:*:*:*
pyopenssl / pyopenssl cpe:2.3:a:pyopenssl:pyopenssl:<26.0.0:*:*:*:*:*:*:*

References