Pyopenssl is a Python wrapper around the OpenSSL cryptographic library, presenting a narrow but strategically embedded attack surface wherever Python applications require TLS or certificate handling. Its documented weaknesses center on memory-safety issues including classic buffer overflows, use-after-free conditions, and improper error handling that reflect the boundary between Python and native C code. Current CVE counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pyopenssl over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27459CRITICAL pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` retu | Mar 18, 2026 | 9.8 | 37 | NO | NO |
CVE-2018-1000807HIGH Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free | Oct 8, 2018 | 8.1 | 27 | NO | NO |
CVE-2026-27448MEDIUM pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` ra | Mar 18, 2026 | 5.3 | 22 | NO | NO |
CVE-2018-1000808MEDIUM Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that | Oct 8, 2018 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pyopenssl.
Media articles that mention a CVE ID that affects a product developed by Pyopenssl — matched by CVE ID, not by vendor name.