pyOpenSSL 26.0.0 was released with fixes for two security vulnerabilities tracked as CVE-2026-27459 and CVE-2026-27448. The first issue is a buffer overflow in DTLS handling that can occur when a cookie callback returns a value longer than DTLS1_COOKIE_LENGTH bytes. The second affects Context.set_tlsext_servername_callback, where exceptions raised by the callback were previously swallowed and the TLS handshake continued as though the callback had completed successfully.
The vulnerabilities were disclosed through the oss-security mailing list and corresponding GitHub security advisories, with dark_haxor credited for reporting CVE-2026-27459 and Leury Castillo credited for reporting CVE-2026-27448. In follow-up discussion, pyOpenSSL maintainer Alex Gaynor said both issues require misbehaving Python code and are therefore unlikely to be exploitable, but the defects were nonetheless corrected in the new release.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
In a follow-up discussion published on 2026-03-20, Alex Gaynor said both vulnerabilities require misbehaving Python code and were therefore unlikely to be exploitable in his opinion. This added impact assessment to the initial release announcement.
On 2026-03-20, pyOpenSSL 26.0.0 was released to fix two security issues: a buffer overflow when a DTLS cookie callback returns an oversized cookie, and improper handling of exceptions in Context.set_tlsext_servername_callback. The release was accompanied by changelog references and GitHub security advisories for both CVEs.
The pyOpenSSL project credited dark_haxor with reporting CVE-2026-27459, a DTLS cookie callback buffer overflow, and Leury Castillo with reporting CVE-2026-27448, an issue where exceptions in a server name callback were silently swallowed and the TLS handshake continued. The exact reporting dates were not provided in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.