
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27448 is a "Failing Open" vulnerability in pyOpenSSL that allows TLS connections to be accepted even when a user-provided set_tlsext_servername_callback callback raises an unhandled exception. This means any security-sensitive logic implemented in that callback — such as hostname validation or access control — could be silently bypassed. The vulnerability affects pyOpenSSL versions 0.14.0 through 25.x, and was fixed in version 26.0.0. It was reported by Leury Castillo and disclosed on March 15, 2026. The CVSS v3.1 base score is 5.3 (Medium), while the CVSS v4.0 base score is 1.7 (Low) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-636 (Not Failing Securely / Failing Open): when a Python exception propagated uncaught through the CFFI callback boundary in the set_tlsext_servername_callback wrapper, the exception was silently swallowed and the TLS handshake was allowed to proceed as if the callback had succeeded. The fix (commit d41a814) wraps the callback invocation in a try/except block; on exception, it calls sys.excepthook with the exception info and returns SSL_TLSEXT_ERR_ALERT_FATAL to abort the handshake. Exploitation requires that the target application uses set_tlsext_servername_callback for security-sensitive decisions and that an attacker can trigger an exception in that callback — for example, by sending a crafted TLS ClientHello with an unexpected or malformed SNI value (GitHub Commit, GitHub Advisory).
Successful exploitation allows a remote, unauthenticated attacker to bypass security controls implemented in the SNI (Server Name Indication) callback, such as hostname-based access restrictions, certificate selection logic, or connection filtering. The primary impact is an integrity violation — unauthorized TLS connections may be accepted that should have been rejected. There is no direct confidentiality or availability impact, but the bypass could enable further attacks depending on what security logic the callback enforces (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported. The EPSS score is approximately 0.04% (14th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on the target application using set_tlsext_servername_callback for security-sensitive behavior and the attacker being able to trigger an exception in that callback, making opportunistic mass exploitation unlikely (GitHub Advisory).
set_tlsext_servername_callback for security-sensitive logic (e.g., hostname-based access control or certificate selection).set_tlsext_servername_callback handler that are not followed by connection termination.The primary remediation is to upgrade pyOpenSSL to version 26.0.0 or later, which ensures that unhandled exceptions in set_tlsext_servername_callback callbacks result in connection rejection via a fatal TLS alert rather than silent acceptance. Downstream products have also issued updates: OpenVPN Access Server 3.2.0 includes pyOpenSSL 26.0.0, Ubuntu issued USN-8115-1, openSUSE and SUSE issued security announcements, and IBM addressed the issue in QRadar Suite Software. As a workaround, ensure all user-provided SNI callbacks include comprehensive exception handling to prevent unhandled exceptions from propagating (GitHub Advisory, OpenVPN Release Notes, IBM Advisory).
The vulnerability received routine coverage across Linux distribution security channels, with Ubuntu, openSUSE, SUSE, and Fedora all issuing advisories and package updates. Red Hat tracked the issue via Bugzilla with a medium severity rating. Microsoft acknowledged the vulnerability in its Security Response Center for Azure Linux components. No significant researcher commentary or social media discussion beyond standard vulnerability aggregator coverage was observed (Red Hat Bugzilla, Microsoft MSRC).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."