{"id":"AZL-80034","summary":"CVE-2026-27459 affecting package pyOpenSSL for versions less than 24.2.1-2","details":"pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.","modified":"2026-08-30T05:26:50Z","published":"2026-03-18T00:16:19Z","upstream":["CVE-2026-27459"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27459"}],"affected":[{"package":{"name":"pyOpenSSL","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/pyOpenSSL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.2.1-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80034.json"}}],"schema_version":"1.9.0"}