pyOpenSSL: DTLS cookie callback buffer overflow

zetlyn/cve-redhat vulnerability cve CVE-2026-27459 known 2026-03-17

https://access.redhat.com/security/cve/CVE-2026-27459

Properties

cvss8.1
receipt
Source
Red Hat
Its words
8.1
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-27459",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:11916",
    "RHSA-2026:48085",
    "RHSA-2026:11856",
    "RHSA-2026:13508",
    "RHSA-2026:13512",
    "RHSA-2026:14835",
    "RHSA-2026:13545",
    "RHSA-2026:19375",
    "RHSA-2026:10754",
    "RHSA-2026:11996",
    "RHSA-2026:68780",
    "RHSA-2026:14874",
    "RHSA-2026:13553",
    "RHSA-2026:14873",
    "RHSA-2026:59153",
    "RHSA-2026:24853",
    "RHSA-2026:22465",
    "RHSA-2026:8437",
    "RHSA-2026:48758",
    "RHSA-2026:21017",
    "RHSA-2026:7224"
  ],
  "affected_packages": [
    "pyopenssl-main-26.0.0-1.1.hum1",
    "ansible-automation-platform-25/ee-supported-rhel8:1777398315",
    "ansible-automation-platform-26/lightspeed-rhel9:1777387242",
    "python3.12-pyOpenSSL-0:26.0.0-2.el9pc",
    "quay/quay-rhel8:1776752646",
    "ansible-automation-platform-26/hub-rhel9:1777299023",
    "automation-controller-0:4.7.11-2.el9ap",
    "ansible-automation-platform-26/ansible-dev-tools-rhel9:1777390240",
    "ansible-automation-platform-27/lightspeed-rhel9:1787217531",
    "python-pyOpenSSL-0:24.1.0-2.el8ui",
    "quay/quay-rhel8:1780891395",
    "ansible-automation-platform-26/eda-controller-rhel9:1777296732",
    "quay/quay-rhel9:1779922205",
    "python-pyOpenSSL-0:25.1.0-0.3.el9pc",
    "quay/quay-rhel9:1779204086",
    "quay/quay-rhel9:1784987273",
    "satellite/iop-vmaas-rhel9:1789611998",
    "jaeger-main-2.20.0-0.8.hum1",
    "quay/quay-rhel8:1779689392",
    "ansible-automation-platform-25/lightspeed-rhel8:1777403872",
    "ansible-automation-platform-27/ee-supported-rhel9:1787235693",
    "ansible-automation-platform-26/platform-resource-runner-rhel9:1777390333",
    "quay/quay-rhel8:1776736910",
    "rhtas/model-transparency-rhel9:1775815407",
    "python-pyOpenSSL-0:24.1.0-2.el8pc",
    "python-pyOpenSSL-0:24.1.0-2.el9pc",
    "quay/quay-rhel8:1776782369",
    "ansible-automation-platform-26/ee-supported-rhel9:1777391447",
    "python3.12-pyOpenSSL-0:26.0.0-1.el9ap",
    "python3.12-pyOpenSSL-0:26.0.0-1.el8ap"
  ],
  "bugzilla": "2448503",
  "bugzilla_description": "pyOpenSSL: DTLS cookie callback buffer overflow",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-03-17T23:34:28Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-27459.json",
  "severity": "important"
}
cweCWE-120
receipt
Source
Red Hat
Its words
CWE-120
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-27459",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:11916",
    "RHSA-2026:48085",
    "RHSA-2026:11856",
    "RHSA-2026:13508",
    "RHSA-2026:13512",
    "RHSA-2026:14835",
    "RHSA-2026:13545",
    "RHSA-2026:19375",
    "RHSA-2026:10754",
    "RHSA-2026:11996",
    "RHSA-2026:68780",
    "RHSA-2026:14874",
    "RHSA-2026:13553",
    "RHSA-2026:14873",
    "RHSA-2026:59153",
    "RHSA-2026:24853",
    "RHSA-2026:22465",
    "RHSA-2026:8437",
    "RHSA-2026:48758",
    "RHSA-2026:21017",
    "RHSA-2026:7224"
  ],
  "affected_packages": [
    "pyopenssl-main-26.0.0-1.1.hum1",
    "ansible-automation-platform-25/ee-supported-rhel8:1777398315",
    "ansible-automation-platform-26/lightspeed-rhel9:1777387242",
    "python3.12-pyOpenSSL-0:26.0.0-2.el9pc",
    "quay/quay-rhel8:1776752646",
    "ansible-automation-platform-26/hub-rhel9:1777299023",
    "automation-controller-0:4.7.11-2.el9ap",
    "ansible-automation-platform-26/ansible-dev-tools-rhel9:1777390240",
    "ansible-automation-platform-27/lightspeed-rhel9:1787217531",
    "python-pyOpenSSL-0:24.1.0-2.el8ui",
    "quay/quay-rhel8:1780891395",
    "ansible-automation-platform-26/eda-controller-rhel9:1777296732",
    "quay/quay-rhel9:1779922205",
    "python-pyOpenSSL-0:25.1.0-0.3.el9pc",
    "quay/quay-rhel9:1779204086",
    "quay/quay-rhel9:1784987273",
    "satellite/iop-vmaas-rhel9:1789611998",
    "jaeger-main-2.20.0-0.8.hum1",
    "quay/quay-rhel8:1779689392",
    "ansible-automation-platform-25/lightspeed-rhel8:1777403872",
    "ansible-automation-platform-27/ee-supported-rhel9:1787235693",
    "ansible-automation-platform-26/platform-resource-runner-rhel9:1777390333",
    "quay/quay-rhel8:1776736910",
    "rhtas/model-transparency-rhel9:1775815407",
    "python-pyOpenSSL-0:24.1.0-2.el8pc",
    "python-pyOpenSSL-0:24.1.0-2.el9pc",
    "quay/quay-rhel8:1776782369",
    "ansible-automation-platform-26/ee-supported-rhel9:1777391447",
    "python3.12-pyOpenSSL-0:26.0.0-1.el9ap",
    "python3.12-pyOpenSSL-0:26.0.0-1.el8ap"
  ],
  "bugzilla": "2448503",
  "bugzilla_description": "pyOpenSSL: DTLS cookie callback buffer overflow",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-03-17T23:34:28Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-27459.json",
  "severity": "important"
}
packagespyopenssl-main-26.0.0-1.1.hum1, ansible-automation-platform-25/ee-supported-rhel8:1777398315, ansible-automation-platform-26/lightspeed-rhel9:1777387242, python3.12-pyOpenSSL-0:26.0.0-2.el9pc, quay/quay-rhel8:1776752646, ansible-automation-platform-26/hub-rhel9:1777299023, automation-controller-0:4.7.11-2.el9ap, ansible-automation-platform-26/ansible-dev-tools-rhel9:1777390240, ansible-automation-platform-27/lightspeed-rhel9:1787217531, python-pyOpenSSL-0:24.1.0-2.el8ui, quay/quay-rhel8:1780891395, ansible-automation-platform-26/eda-controller-rhel9:1777296732, quay/quay-rhel9:1779922205, python-pyOpenSSL-0:25.1.0-0.3.el9pc, quay/quay-rhel9:1779204086, quay/quay-rhel9:1784987273, satellite/iop-vmaas-rhel9:1789611998, jaeger-main-2.20.0-0.8.hum1, quay/quay-rhel8:1779689392, ansible-automation-platform-25/lightspeed-rhel8:1777403872, ansible-automation-platform-27/ee-supported-rhel9:1787235693, ansible-automation-platform-26/platform-resource-runner-rhel9:1777390333, quay/quay-rhel8:1776736910, rhtas/model-transparency-rhel9:1775815407, python-pyOpenSSL-0:24.1.0-2.el8pc, python-pyOpenSSL-0:24.1.0-2.el9pc, quay/quay-rhel8:1776782369, ansible-automation-platform-26/ee-supported-rhel9:1777391447, python3.12-pyOpenSSL-0:26.0.0-1.el9ap, python3.12-pyOpenSSL-0:26.0.0-1.el8ap
receipt
Source
Red Hat
Its words
pyopenssl-main-26.0.0-1.1.hum1, ansible-automation-platform-25/ee-supported-rhel8:1777398315, ansible-automation-platform-26/lightspeed-rhel9:1777387242, python3.12-pyOpenSSL-0:26.0.0-2.el9pc, quay/quay-rhel8:1776752646, ansible-automation-platform-26/hub-rhel9:1777299023, automation-controller-0:4.7.11-2.el9ap, ansible-automation-platform-26/ansible-dev-tools-rhel9:1777390240, ansible-automation-platform-27/lightspeed-rhel9:1787217531, python-pyOpenSSL-0:24.1.0-2.el8ui, quay/quay-rhel8:1780891395, ansible-automation-platform-26/eda-controller-rhel9:1777296732, quay/quay-rhel9:1779922205, python-pyOpenSSL-0:25.1.0-0.3.el9pc, quay/quay-rhel9:1779204086, quay/quay-rhel9:1784987273, satellite/iop-vmaas-rhel9:1789611998, jaeger-main-2.20.0-0.8.hum1, quay/quay-rhel8:1779689392, ansible-automation-platform-25/lightspeed-rhel8:1777403872, ansible-automation-platform-27/ee-supported-rhel9:1787235693, ansible-automation-platform-26/platform-resource-runner-rhel9:1777390333, quay/quay-rhel8:1776736910, rhtas/model-transparency-rhel9:1775815407, python-pyOpenSSL-0:24.1.0-2.el8pc, python-pyOpenSSL-0:24.1.0-2.el9pc, quay/quay-rhel8:1776782369, ansible-automation-platform-26/ee-supported-rhel9:1777391447, python3.12-pyOpenSSL-0:26.0.0-1.el9ap, python3.12-pyOpenSSL-0:26.0.0-1.el8ap
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-27459",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:11916",
    "RHSA-2026:48085",
    "RHSA-2026:11856",
    "RHSA-2026:13508",
    "RHSA-2026:13512",
    "RHSA-2026:14835",
    "RHSA-2026:13545",
    "RHSA-2026:19375",
    "RHSA-2026:10754",
    "RHSA-2026:11996",
    "RHSA-2026:68780",
    "RHSA-2026:14874",
    "RHSA-2026:13553",
    "RHSA-2026:14873",
    "RHSA-2026:59153",
    "RHSA-2026:24853",
    "RHSA-2026:22465",
    "RHSA-2026:8437",
    "RHSA-2026:48758",
    "RHSA-2026:21017",
    "RHSA-2026:7224"
  ],
  "affected_packages": [
    "pyopenssl-main-26.0.0-1.1.hum1",
    "ansible-automation-platform-25/ee-supported-rhel8:1777398315",
    "ansible-automation-platform-26/lightspeed-rhel9:1777387242",
    "python3.12-pyOpenSSL-0:26.0.0-2.el9pc",
    "quay/quay-rhel8:1776752646",
    "ansible-automation-platform-26/hub-rhel9:1777299023",
    "automation-controller-0:4.7.11-2.el9ap",
    "ansible-automation-platform-26/ansible-dev-tools-rhel9:1777390240",
    "ansible-automation-platform-27/lightspeed-rhel9:1787217531",
    "python-pyOpenSSL-0:24.1.0-2.el8ui",
    "quay/quay-rhel8:1780891395",
    "ansible-automation-platform-26/eda-controller-rhel9:1777296732",
    "quay/quay-rhel9:1779922205",
    "python-pyOpenSSL-0:25.1.0-0.3.el9pc",
    "quay/quay-rhel9:1779204086",
    "quay/quay-rhel9:1784987273",
    "satellite/iop-vmaas-rhel9:1789611998",
    "jaeger-main-2.20.0-0.8.hum1",
    "quay/quay-rhel8:1779689392",
    "ansible-automation-platform-25/lightspeed-rhel8:1777403872",
    "ansible-automation-platform-27/ee-supported-rhel9:1787235693",
    "ansible-automation-platform-26/platform-resource-runner-rhel9:1777390333",
    "quay/quay-rhel8:1776736910",
    "rhtas/model-transparency-rhel9:1775815407",
    "python-pyOpenSSL-0:24.1.0-2.el8pc",
    "python-pyOpenSSL-0:24.1.0-2.el9pc",
    "quay/quay-rhel8:1776782369",
    "ansible-automation-platform-26/ee-supported-rhel9:1777391447",
    "python3.12-pyOpenSSL-0:26.0.0-1.el9ap",
    "python3.12-pyOpenSSL-0:26.0.0-1.el8ap"
  ],
  "bugzilla": "2448503",
  "bugzilla_description": "pyOpenSSL: DTLS cookie callback buffer overflow",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-03-17T23:34:28Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-27459.json",
  "severity": "important"
}
severityimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-27459",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:11916",
    "RHSA-2026:48085",
    "RHSA-2026:11856",
    "RHSA-2026:13508",
    "RHSA-2026:13512",
    "RHSA-2026:14835",
    "RHSA-2026:13545",
    "RHSA-2026:19375",
    "RHSA-2026:10754",
    "RHSA-2026:11996",
    "RHSA-2026:68780",
    "RHSA-2026:14874",
    "RHSA-2026:13553",
    "RHSA-2026:14873",
    "RHSA-2026:59153",
    "RHSA-2026:24853",
    "RHSA-2026:22465",
    "RHSA-2026:8437",
    "RHSA-2026:48758",
    "RHSA-2026:21017",
    "RHSA-2026:7224"
  ],
  "affected_packages": [
    "pyopenssl-main-26.0.0-1.1.hum1",
    "ansible-automation-platform-25/ee-supported-rhel8:1777398315",
    "ansible-automation-platform-26/lightspeed-rhel9:1777387242",
    "python3.12-pyOpenSSL-0:26.0.0-2.el9pc",
    "quay/quay-rhel8:1776752646",
    "ansible-automation-platform-26/hub-rhel9:1777299023",
    "automation-controller-0:4.7.11-2.el9ap",
    "ansible-automation-platform-26/ansible-dev-tools-rhel9:1777390240",
    "ansible-automation-platform-27/lightspeed-rhel9:1787217531",
    "python-pyOpenSSL-0:24.1.0-2.el8ui",
    "quay/quay-rhel8:1780891395",
    "ansible-automation-platform-26/eda-controller-rhel9:1777296732",
    "quay/quay-rhel9:1779922205",
    "python-pyOpenSSL-0:25.1.0-0.3.el9pc",
    "quay/quay-rhel9:1779204086",
    "quay/quay-rhel9:1784987273",
    "satellite/iop-vmaas-rhel9:1789611998",
    "jaeger-main-2.20.0-0.8.hum1",
    "quay/quay-rhel8:1779689392",
    "ansible-automation-platform-25/lightspeed-rhel8:1777403872",
    "ansible-automation-platform-27/ee-supported-rhel9:1787235693",
    "ansible-automation-platform-26/platform-resource-runner-rhel9:1777390333",
    "quay/quay-rhel8:1776736910",
    "rhtas/model-transparency-rhel9:1775815407",
    "python-pyOpenSSL-0:24.1.0-2.el8pc",
    "python-pyOpenSSL-0:24.1.0-2.el9pc",
    "quay/quay-rhel8:1776782369",
    "ansible-automation-platform-26/ee-supported-rhel9:1777391447",
    "python3.12-pyOpenSSL-0:26.0.0-1.el9ap",
    "python3.12-pyOpenSSL-0:26.0.0-1.el8ap"
  ],
  "bugzilla": "2448503",
  "bugzilla_description": "pyOpenSSL: DTLS cookie callback buffer overflow",
  "cvss3_score": "8.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-03-17T23:34:28Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-27459.json",
  "severity": "important"
}

Text

pyOpenSSL: DTLS cookie callback buffer overflow