CVE-2026-27459
If a user provided callback to setcookiegenerate_callback returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer.
Cookie values that are too long are now rejected.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4, https://nvd.nist.gov/vuln/detail/CVE-2026-27459, https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408, https://github.com/pyca/pyopenssl, https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst
