CVE-2026-27448

Aliases:GHSA-vp96-hxj8-p424ECHO-e106-5b29-8a6fPYSEC-2026-2268SUSE-SU-2026:3424-1DEBIAN-CVE-2026-27448CGA-24v8-7jq6-xgf6CGA-3vcx-hqj5-4749CGA-4c88-m7r8-hp53CGA-62jp-wr7j-8p86CGA-6cw9-jw5m-3j56CGA-7rgm-69m6-jc3qCGA-87fv-pfhr-6g8xCGA-94x7-fxfc-39rpCGA-97vh-wqp4-9xrwCGA-9w87-5p6h-jgh5CGA-f66p-r5p7-gj8jCGA-fmcq-72p6-f8x7CGA-fvmp-g46q-rwr2CGA-fvp4-fppm-v69pCGA-gm8r-9cqc-mvhpCGA-gq7p-j83r-jq3xCGA-jx8q-hmcq-vx9vCGA-mf69-hjqm-568vCGA-phmh-82rx-gfh5CGA-228x-4c95-xg8gCGA-237r-c5h7-m2j3CGA-33r2-73gg-58qcCGA-3cwf-8v6f-f7hgCGA-3w5f-x58f-6rhwCGA-4hwp-h35m-h59vCGA-4jfc-3ghg-8hrcCGA-4jvx-xw8x-5fpwCGA-5589-7qww-8975CGA-58fh-gv4v-g6g6CGA-5mcp-5qhh-v3rpCGA-5vqc-pwgq-hgg9CGA-5xpf-v94w-h72rCGA-666g-75rw-8qfmCGA-7f7r-hrmj-pg92CGA-7rh5-9939-68q9CGA-83hf-wq85-hf75CGA-8c8v-mq92-w2wqCGA-8v9v-fj7v-pp3fCGA-8v9x-c2x3-vvr3CGA-9h2m-ww25-fm6rCGA-9v9r-9wv7-68h4CGA-c23v-2788-6j6fCGA-chfg-g7h7-cvf2CGA-cmw4-gpcr-pwx6CGA-g7mg-vrr4-8rmcCGA-h6f7-fg28-mq95CGA-hgjc-37ch-96x4CGA-hgvv-f735-4c3jCGA-hrmv-c4j8-45j2CGA-j62w-gxgc-296vCGA-j7cq-82j8-hr3pCGA-jcm4-6397-m2vgCGA-jm23-3g5p-699cCGA-jvp9-jm52-8c5rCGA-m6wf-jj3c-2c8gCGA-m7j2-jvmh-8x78CGA-mfq8-j67q-7p76CGA-pxg2-3gm4-c4mhCGA-qfp8-gr7m-xgc6CGA-qh3c-q9jh-hm3mCGA-qh6g-6xwv-9qr3CGA-qwr6-4j2j-8j6vCGA-qxqp-5w45-jjg2CGA-r3gp-w4vm-824rCGA-r3mv-r5x2-25m4CGA-r5v9-987r-6jggCGA-r8qv-pwfq-vmgvCGA-rjr6-wxrx-543jCGA-rqvx-rqrc-h823CGA-rvvf-4774-c62hCGA-rxp8-c2x3-fw2vCGA-vw9m-8c2g-mpvcCGA-w475-r643-qx59CGA-w692-mqff-73f5CGA-ww6r-7fvj-rp3fCGA-x2xr-7q3c-qfwrCGA-x47g-g26x-3v62CGA-x68f-g746-crjhCGA-x9pf-xv26-fq2pCGA-xcj4-p88j-gp28CGA-xhg2-fh9c-5v4fCGA-xxmw-xgcr-xmg8CGA-vx33-r88h-r7f4
Analyzed
Published: 17 Mar 2026, 23:24
Last modified:18 Mar 2026, 20:18

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
0.24% LOW
0% probability +0.20%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Mar 2026, 23:24
Published
Vulnerability first disclosed
18 Mar 2026, 20:18
Last Modified
Vulnerability information updated

Description

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.

CVSS Metrics

  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U
  • v4.0LOWScore: 1.7CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS Trends

Current EPSS score: 0.24% Percentile: 16%

Techniques & Countermeasures

  • CWE-636Not Failing Securely ('Failing Open')

    When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Affected Systems

  • chainguardairflow-2

    < 2.11.2-r2

  • chainguardairflow-3

    < 3.1.8-r8

  • chainguardauthentik

    < 2026.2.1-r4

  • chainguardauthentik-fips

    < 2026.2.1-r3

  • chainguardawx

    < 24.6.1-r31

  • chainguardaz

    < 2.84.0-r3

  • chainguarddatadog-agent-7.71-core-integrations

    all

  • chainguarddatadog-agent-7.72-core-integrations

    all

  • chainguarddatadog-agent-7.73-core-integrations

    < 7.73.3-r23

  • chainguarddatadog-agent-7.74-core-integrations

    < 7.74.1-r24

  • chainguarddatadog-agent-7.75-core-integrations

    all

  • chainguarddatadog-agent-7.76

    < 7.76.3-r41

  • chainguarddatadog-agent-7.76-core-integrations

    < 7.76.3-r32

  • chainguarddatadog-agent-7.77-core-integrations

    < 7.77.3-r5

  • chainguarddatadog-agent-fips-7.71-core-integrations

    < 7.71.2-r20 | < 7.71.2-r19

  • chainguarddatadog-agent-fips-7.72-core-integrations

    all

  • chainguarddatadog-agent-fips-7.73-core-integrations

    < 7.73.3-r26

  • chainguarddatadog-agent-fips-7.74-core-integrations

    < 7.74.1-r26

  • chainguarddatadog-agent-fips-7.75-core-integrations

    all

  • chainguarddatadog-agent-fips-7.76-core-integrations

    < 7.76.3-r32

  • chainguarddatadog-agent-fips-7.77-core-integrations

    < 7.77.3-r5

  • chainguarddatahub-ingestion

    < 1.5.0.1-r0

  • chainguarddbt-snowflake

    all

  • chainguardggshield

    < 1.51.0-r1

  • chainguardgitlab-toolbox-ce-18.7

    < 18.7.5-r1

  • chainguardgitlab-toolbox-ce-18.8

    < 18.8.5-r2

  • chainguardgitlab-toolbox-ce-18.9

    < 18.9.2-r1

  • chainguardgitlab-toolbox-ce-fips-18.7

    < 18.7.5-r1

  • chainguardgitlab-toolbox-ce-fips-18.8

    < 18.8.5-r1

  • chainguardgitlab-toolbox-ce-fips-18.9

    < 18.9.2-r1

  • chainguardgitlab-toolbox-ce-fips-19.0

    < 19.0.2-r1

  • chainguardkeep-api

    < 0.51.0-r0

  • chainguardkeep-api-fips

    < 0.51.0-r0

  • chainguardlocalstack

    < 4.14.0-r4

  • chainguardmitmproxy

    < 12.2.1-r0 | < 12.2.3-r0

  • chainguardpy3-cassandra-medusa

    < 0.27.0-r5

  • chainguardpy3.13-duplicity

    all

  • chainguardrequest-1276

    < 0.27.0-r6

  • chainguardsuperset-5.0

    < 5.0.0-r20

  • chainguardsuperset-6.0

    < 6.0.0-r4

  • wolfiairflow-3

    < 3.1.8-r8

  • wolfiaz

    < 2.84.0-r3

  • wolfidatadog-agent-7.72-core-integrations

    all

  • wolfidatadog-agent-7.73-core-integrations

    < 7.73.3-r23

  • wolfidatadog-agent-7.74-core-integrations

    < 7.74.1-r24

  • wolfidatadog-agent-7.75-core-integrations

    all

  • wolfidatadog-agent-7.76

    < 7.76.3-r41

  • wolfidatadog-agent-7.76-core-integrations

    < 7.76.3-r32

  • wolfidatadog-agent-7.77-core-integrations

    < 7.77.3-r5

  • wolfiggshield

    < 1.51.0-r1

Showing first 50 affected entries in server-rendered view.

References (10)