CVE-2026-27459: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27459 is a classic buffer overflow vulnerability in pyOpenSSL, a Python wrapper around the OpenSSL library, specifically affecting the DTLS cookie generation callback mechanism. When a user-provided callback registered via set_cookie_generate_callback returns a cookie value exceeding 256 bytes (the DTLS1_COOKIE_LENGTH limit), pyOpenSSL copies the oversized value into a fixed-size OpenSSL-provided buffer without enforcing a length check, corrupting adjacent memory. The vulnerability affects pyOpenSSL versions 22.0.0 through 25.x.x and was disclosed on March 15, 2026, with a patch released in version 26.0.0 (GitHub Advisory). It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.2 (High) (GitHub Advisory).

Technical details

The root cause is CWE-120 (Buffer Copy without Checking Size of Input — Classic Buffer Overflow). In the _CookieGenerateCallbackHelper class within src/OpenSSL/SSL.py, the wrapper function copied user-returned cookie bytes directly into a native OpenSSL buffer (out[0:len(cookie)] = cookie) without verifying that the cookie length did not exceed DTLS1_COOKIE_LENGTH (255 bytes), allowing adjacent memory to be overwritten (pyca/pyopenssl commit). The attack vector is network-based and targets the DTLS handshake process: a client initiates a DTLS handshake, the server calls DTLSv1_listen(), which triggers the cookie generation callback; if that callback returns more than 256 bytes, the overflow occurs (GitHub Advisory). Exploitation requires that the application uses a custom set_cookie_generate_callback that can be influenced to return an oversized value, and that the DTLS server is network-accessible. The fix adds a length check before copying: if len(cookie) > max_cookie_len, a ValueError is raised and the oversized value is rejected (pyca/pyopenssl commit).

Impact

Successful exploitation can result in heap/stack memory corruption, potentially leading to arbitrary code execution, information disclosure, or denial of service on the affected system (GitHub Advisory). The vulnerability impacts all three security pillars — confidentiality, integrity, and availability — with high impact ratings across each in the CVSS scoring. Affected deployments include any Python application using pyOpenSSL 22.0.0–25.x.x with a custom DTLS cookie generation callback, as well as downstream products such as OpenVPN Access Server (prior to 3.2.0), IBM QRadar Suite Software, Red Hat Ansible Automation Platform, Red Hat Satellite, and Microsoft Azure Linux packages (OpenVPN Release Notes, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code has been reported, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.04% (0.000400000), indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a specific deployment condition — the application must use a custom DTLS cookie callback that can be manipulated to return oversized values — which limits the practical attack surface despite the high CVSS score.

Exploitation steps

  1. Reconnaissance: Identify network-accessible services using pyOpenSSL 22.0.0–25.x.x with DTLS enabled and a custom set_cookie_generate_callback registered. Tools like Shodan or Censys can identify DTLS-enabled endpoints.
  2. Initiate DTLS Handshake: Send a DTLS ClientHello packet to the target server to trigger the DTLS handshake process.
  3. Trigger Cookie Generation: The server calls DTLSv1_listen() in response to the ClientHello, which internally invokes the user-registered cookie generation callback.
  4. Overflow the Buffer: If the attacker can influence the callback to return a cookie value exceeding 255 bytes (e.g., by controlling application-layer input that feeds into the callback logic), the oversized value is copied into the fixed-size OpenSSL buffer without bounds checking, corrupting adjacent memory.
  5. Achieve Impact: Depending on memory layout and the specific application, the memory corruption may lead to a crash (denial of service), information leakage from adjacent memory, or potentially arbitrary code execution (pyca/pyopenssl commit, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or malformed DTLS ClientHello packets from external sources targeting DTLS-enabled services; anomalous UDP traffic patterns on DTLS ports (typically 443 or 4433).
  • Logs: Application crashes or unhandled exceptions in Python processes using pyOpenSSL during DTLS handshake phases; error messages referencing DTLSv1_listen or cookie generation failures.
  • Process: Unexpected termination or segmentation faults in Python processes wrapping OpenSSL DTLS functionality; core dump files generated by the affected service process.
  • File System: Core dump files (e.g., core, core.<pid>) in the working directory of the affected application, potentially containing sensitive memory contents.

Mitigation and workarounds

The primary remediation is to upgrade pyOpenSSL to version 26.0.0 or later, which rejects cookie values exceeding DTLS1_COOKIE_LENGTH bytes before copying them into the OpenSSL buffer (GitHub Advisory, pyca/pyopenssl commit). Downstream products have also released patches: OpenVPN Access Server 3.2.0 includes the updated pyOpenSSL 26.0.0 (OpenVPN Release Notes); Red Hat has issued errata RHSA-2026:10754, RHSA-2026:13508, RHSA-2026:13512, RHSA-2026:14873, and RHSA-2026:14874 for affected products (Red Hat Bugzilla). As a temporary workaround for systems that cannot be immediately patched, ensure that any custom set_cookie_generate_callback implementation enforces a maximum cookie length of 255 bytes, and restrict network access to DTLS-enabled services where possible.

Community reactions

The vulnerability was reported by researcher justlife4x4 and disclosed by the pyca/pyopenssl maintainers on March 15, 2026 (GitHub Advisory). Red Hat tracked the issue via Bugzilla with high priority and coordinated patches across multiple product lines including Ansible Automation Platform and Red Hat Satellite (Red Hat Bugzilla). The vulnerability was also discussed on the oss-security mailing list and received coverage from Linux security news outlets including pro-linux.de and linuxsecurity.com, reflecting broad awareness in the open-source security community.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pyopenssl

Affected

sid

pyopenssl: 26.0.0-1

Fixed

trixie

pyopenssl: 25.0.0-1+deb13u1

Fixed

RHEL / CentOS

Affected

OpenShift

Not Affected

RHEL 8

Not Affected

Alpine

Fixed

edge

py3-openssl: 26.1.0-r0

Fixed

v3.23

py3-openssl: 26.1.0-r0

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management