{"id":"AZL-80031","summary":"CVE-2026-27448 affecting package pyOpenSSL for versions less than 24.2.1-2","details":"pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.","modified":"2026-09-09T05:29:25Z","published":"2026-03-18T00:16:19Z","upstream":["CVE-2026-27448"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27448"}],"affected":[{"package":{"name":"pyOpenSSL","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/pyOpenSSL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.2.1-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80031.json"}}],"schema_version":"1.9.0"}