Логотип exploitDog
bind:CVE-2026-27448
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-27448

Количество 6

Количество 6

ubuntu логотип

CVE-2026-27448

9 дней назад

(pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in ...)

EPSS: Низкий
redhat логотип

CVE-2026-27448

9 дней назад

A flaw was found in pyOpenSSL. The set_tlsext_servername_callback callback function can be used to implement Server Name Indication (SNI) during the TLS handshake. When the callback raises an unhandled exception, the handshake incorrectly proceeds instead of terminating. This fail-open behavior can allow an attacker to bypass SNI-based security controls and access restricted endpoints.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-27448

9 дней назад

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.

EPSS: Низкий
msrc логотип

CVE-2026-27448

8 дней назад

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

EPSS: Низкий
debian логотип

CVE-2026-27448

9 дней назад

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in ...

EPSS: Низкий
github логотип

GHSA-vp96-hxj8-p424

10 дней назад

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-27448

(pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in ...)

0%
Низкий
9 дней назад
redhat логотип
CVE-2026-27448

A flaw was found in pyOpenSSL. The set_tlsext_servername_callback callback function can be used to implement Server Name Indication (SNI) during the TLS handshake. When the callback raises an unhandled exception, the handshake incorrectly proceeds instead of terminating. This fail-open behavior can allow an attacker to bypass SNI-based security controls and access restricted endpoints.

CVSS3: 5.4
0%
Низкий
9 дней назад
nvd логотип
CVE-2026-27448

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.

0%
Низкий
9 дней назад
msrc логотип
CVE-2026-27448

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

0%
Низкий
8 дней назад
debian логотип
CVE-2026-27448

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in ...

0%
Низкий
9 дней назад
github логотип
GHSA-vp96-hxj8-p424

pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback

0%
Низкий
10 дней назад

Уязвимостей на страницу