
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27459 is a classic buffer overflow vulnerability in pyOpenSSL, a Python wrapper around the OpenSSL library, specifically affecting the DTLS cookie generation callback mechanism. When a user-provided callback registered via set_cookie_generate_callback returns a cookie value exceeding 256 bytes (the DTLS1_COOKIE_LENGTH limit), pyOpenSSL copies the oversized value into a fixed-size OpenSSL-provided buffer without enforcing a length check, corrupting adjacent memory. The vulnerability affects pyOpenSSL versions 22.0.0 through 25.x.x and was disclosed on March 15, 2026, with a patch released in version 26.0.0 (GitHub Advisory). It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.2 (High) (GitHub Advisory).
The root cause is CWE-120 (Buffer Copy without Checking Size of Input — Classic Buffer Overflow). In the _CookieGenerateCallbackHelper class within src/OpenSSL/SSL.py, the wrapper function copied user-returned cookie bytes directly into a native OpenSSL buffer (out[0:len(cookie)] = cookie) without verifying that the cookie length did not exceed DTLS1_COOKIE_LENGTH (255 bytes), allowing adjacent memory to be overwritten (pyca/pyopenssl commit). The attack vector is network-based and targets the DTLS handshake process: a client initiates a DTLS handshake, the server calls DTLSv1_listen(), which triggers the cookie generation callback; if that callback returns more than 256 bytes, the overflow occurs (GitHub Advisory). Exploitation requires that the application uses a custom set_cookie_generate_callback that can be influenced to return an oversized value, and that the DTLS server is network-accessible. The fix adds a length check before copying: if len(cookie) > max_cookie_len, a ValueError is raised and the oversized value is rejected (pyca/pyopenssl commit).
Successful exploitation can result in heap/stack memory corruption, potentially leading to arbitrary code execution, information disclosure, or denial of service on the affected system (GitHub Advisory). The vulnerability impacts all three security pillars — confidentiality, integrity, and availability — with high impact ratings across each in the CVSS scoring. Affected deployments include any Python application using pyOpenSSL 22.0.0–25.x.x with a custom DTLS cookie generation callback, as well as downstream products such as OpenVPN Access Server (prior to 3.2.0), IBM QRadar Suite Software, Red Hat Ansible Automation Platform, Red Hat Satellite, and Microsoft Azure Linux packages (OpenVPN Release Notes, Red Hat Bugzilla).
No public proof-of-concept exploit code has been reported, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.04% (0.000400000), indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a specific deployment condition — the application must use a custom DTLS cookie callback that can be manipulated to return oversized values — which limits the practical attack surface despite the high CVSS score.
set_cookie_generate_callback registered. Tools like Shodan or Censys can identify DTLS-enabled endpoints.DTLSv1_listen() in response to the ClientHello, which internally invokes the user-registered cookie generation callback.DTLSv1_listen or cookie generation failures.core, core.<pid>) in the working directory of the affected application, potentially containing sensitive memory contents.The primary remediation is to upgrade pyOpenSSL to version 26.0.0 or later, which rejects cookie values exceeding DTLS1_COOKIE_LENGTH bytes before copying them into the OpenSSL buffer (GitHub Advisory, pyca/pyopenssl commit). Downstream products have also released patches: OpenVPN Access Server 3.2.0 includes the updated pyOpenSSL 26.0.0 (OpenVPN Release Notes); Red Hat has issued errata RHSA-2026:10754, RHSA-2026:13508, RHSA-2026:13512, RHSA-2026:14873, and RHSA-2026:14874 for affected products (Red Hat Bugzilla). As a temporary workaround for systems that cannot be immediately patched, ensure that any custom set_cookie_generate_callback implementation enforces a maximum cookie length of 255 bytes, and restrict network access to DTLS-enabled services where possible.
The vulnerability was reported by researcher justlife4x4 and disclosed by the pyca/pyopenssl maintainers on March 15, 2026 (GitHub Advisory). Red Hat tracked the issue via Bugzilla with high priority and coordinated patches across multiple product lines including Ansible Automation Platform and Red Hat Satellite (Red Hat Bugzilla). The vulnerability was also discussed on the oss-security mailing list and received coverage from Linux security news outlets including pro-linux.de and linuxsecurity.com, reflecting broad awareness in the open-source security community.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."