CVE-2026-27448 identifies a vulnerability in pyOpenSSL versions 0.14.0 through 25.x.x, where an unhandled exception in a user-provided `set_tlsext_servername_callback` could cause a connection to be accepted. This bypasses security-sensitive checks implemented within the callback, potentially leading to an integrity compromise. Rated as Medium severity (CVSS 5.3), the vulnerability has a network attack vector and low attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community attention for this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.14, < 26.0.0CPE matchmatch criteria | cpe:2.3:a:pyopenssl:pyopenssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
pyOpenSSL vulnerability
May 28, 2026pyOpenSSL vulnerabilities
Mar 23, 2026pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
Mar 16, 2026pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
Mar 10, 2026