🛡️ OESA-2026-1731 — pyopenssl
Description
pyOpenSSL security update
pyOpenSSL is a rather thin wrapper around (a subset of) the OpenSSL library. With thin wrapper we mean that a lot of the object methods do nothing more than calling a corresponding function in the OpenSSL library.
Security Fix(es):
A security vulnerability exists in the PyOpenSSL library's set_tlsext_servername_callback function. When a user-provided callback function raises an unhandled exception, the connection would still be accepted. If a user relies on this callback for any security-sensitive behavior (such as server name-based access control or certificate validation), this vulnerability could allow the security mechanism to be bypassed, potentially permitting unauthorized connections or access.(CVE-2026-27448)
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to set_cookie_generate_callback returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.(CVE-2026-27459)
Affected software
OESA-2026-1731 is recorded against 1 package.
- pyopenssl (fixed in 24.0.0-3.oe2403sp3)
Timeline and source
Published on 27 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.openeuler.org (Advisory)
nvd.nist.gov (Advisory)
nvd.nist.gov (Advisory)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| pyopenssl | — | 24.0.0-3.oe2403sp3 |
References
Similar Threats
- Unknown CLSA-2026-1775781161
- Unknown CLSA-2026-1775781163
- Unknown CLSA-2026-1775781164
- Critical OESA-2026-1729
- Critical OESA-2026-1730
More OESA 2026 advisories
Browse all of OESA 2026 in the advisory index.
Exploit Protection
Are you running pyopenssl?
OESA-2026-1731 carries CVSS 9.5 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.
Check My Site For OESA-2026-1731 →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.