pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
CVSS Details
- CVSS 4.0 Base Score: 7.2 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-openssl | Apr 27, 2026 | Mar 17, 2026 |
| Debian | — | Upgrade pyopenssl | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | Upgrade python3.12-galaxy-ngUpgrade python3.12-django-ansible-base+resource_registryUpgrade automation-gateway-proxy-server-debuginfoUpgrade python3.12-pyasn1Upgrade automation-controller-cliUpgrade automation-gatewayUpgrade python3.12-galaxy-importerUpgrade automation-controller-uiUpgrade python3.12-pathspecUpgrade python3.12-cffiUpgrade python3.12-pulpcoreUpgrade python3.12-pysequoiaUpgrade automation-gateway-proxyUpgrade python3.12-django-ansible-base+activitystreamUpgrade python3.12-django-ansible-base+api_documentationUpgrade receptorUpgrade python3.12-cryptography-debuginfoUpgrade ansible-coreUpgrade python3.12-cffi-debuginfoUpgrade python-pytokens-debugsourceUpgrade automation-eda-controller-worker-servicesUpgrade python3.12-cryptography-debugsourceUpgrade python3.12-jwcryptoUpgrade automation-eda-controller-base-servicesUpgrade automation-hubUpgrade python3-pathspecUpgrade python3.12-dynaconfUpgrade receptor-debuginfoUpgrade automation-controller-serverUpgrade python3-pytokens-debuginfoUpgrade automation-eda-controller-event-stream-servicesUpgrade python3.12-pysequoia-debugsourceUpgrade ansible-testUpgrade python3.12-django-ansible-base+rbacUpgrade python3-pytokensUpgrade automation-controller-venv-towerUpgrade python3-wheel-wheelUpgrade receptorctlUpgrade python3.12-blackUpgrade python3.12-django-ansible-baseUpgrade python3-blackUpgrade automation-eda-controller-baseUpgrade yamllintUpgrade python3.12-markdownUpgrade automation-gateway-proxy-debugsourceUpgrade python3.12-pyjwt+cryptoUpgrade receptor-debugsourceUpgrade python3.12-django-ansible-base+redis_clientUpgrade automation-eda-controllerUpgrade python3.12-cryptographyUpgrade python3.12-cffi-debugsourceUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade automation-controllerUpgrade python3.12-django-ansible-base+feature_flagsUpgrade python3.12-pytokens-debugsourceUpgrade automation-gateway-proxy-serverUpgrade ansible-lintUpgrade automation-gateway-serverUpgrade automation-platform-uiUpgrade python3.12-pyOpenSSLUpgrade python3.12-django-ansible-base+rest_filtersUpgrade python3.12-django-ansible-base+channel_authUpgrade python3.12-pulp-containerUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade python3.12-pyasn1-modulesUpgrade python3.12-pytokens-debuginfoUpgrade python3.12-django-ansible-base+authenticationUpgrade python3.12-pytokensUpgrade python3.12-pysequoia-debuginfoUpgrade python3.12-pyjwtUpgrade automation-gateway-config | May 6, 2026 | Mar 17, 2026 |
| Ubuntu | — | Upgrade python3-openssl | Mar 24, 2026 | Mar 23, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub