Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vp96-hxj8-p424

Опубликовано: 16 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 1.7

Описание

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

If a user provided callback to set_tlsext_servername_callback raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it.

Unhandled exceptions now result in rejecting the connection.

Credit to Leury Castillo for reporting this issue.

Пакеты

Наименование

pyopenssl

pip
Затронутые версииВерсия исправления

>= 0.14.0, < 26.0.0

26.0.0

EPSS

Процентиль: 15%
0.00241
Низкий

1.7 Low

CVSS4

Дефекты

CWE-636

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.

CVSS3: 5.4
redhat
5 месяцев назад

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.

CVSS3: 5.3
nvd
5 месяцев назад

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.

msrc
4 месяца назад

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

CVSS3: 5.3
debian
5 месяцев назад

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in ...

EPSS

Процентиль: 15%
0.00241
Низкий

1.7 Low

CVSS4

Дефекты

CWE-636