<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:32:17.922642+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-27448</id>
    <title>BELL-CVE-2026-27448</title>
    <updated>2026-10-03T12:32:18.758505+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: py3-openssl, Alpaquita:stream: py3-openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-27448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2026-27448</id>
    <title>BREW-aws-sam-cli-CVE-2026-27448 — pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback</title>
    <updated>2026-10-03T12:32:18.758564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aws-sam-cli</p>
<p>If a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it.</p>
<p>Unhandled exceptions now result in rejecting the connection.</p>
<p>Credit to **Leury Castillo** for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aws-sam-cli-cve-2026-27448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0341</id>
    <title>certfr-2026-avi-0341 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-03T12:32:18.758594+00:00</updated>
    <content>certfr-2026-avi-0341</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0341"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</id>
    <title>Withdrawn: CLEANSTART-2026-AZ09261 — Security fixes for CVE-2023-46136, CVE-2024-12797, CVE-2024-34069, CVE-2024-49766, CVE-2024-49767, CVE-2025-62727, CVE-…</title>
    <updated>2026-10-03T12:32:18.758612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276533</id>
    <title>EUVD-2026-276533</title>
    <updated>2026-10-03T12:32:18.758640+00:00</updated>
    <content>EUVD-2026-276533</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27448</id>
    <title>fkie_cve-2026-27448</title>
    <updated>2026-10-03T12:32:18.758653+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vp96-hxj8-p424</id>
    <title>GHSA-vp96-hxj8-p424 — pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback</title>
    <updated>2026-10-03T12:32:18.758683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyopenssl</p>
<p>If a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it.</p>
<p>Unhandled exceptions now result in rejecting the connection.</p>
<p>Credit to **Leury Castillo** for reporting this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vp96-hxj8-p424"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-27448</id>
    <title>msrc_CVE-2026-27448 — pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback</title>
    <updated>2026-10-03T12:32:18.758705+00:00</updated>
    <content>msrc_CVE-2026-27448</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-27448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1729</id>
    <title>OESA-2026-1729 — pyOpenSSL security update</title>
    <updated>2026-10-03T12:32:18.758721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: pyOpenSSL</p>
<p>pyOpenSSL is a rather thin wrapper around (a subset of) the OpenSSL library. With thin wrapper we mean that a lot of the object methods do nothing more than calling a corresponding function in the OpenSSL library.

Security Fix(es):</p>
<p>A security vulnerability exists in the PyOpenSSL library&amp;apos;s `set_tlsext_servername_callback` function. When a user-provided callback function raises an unhandled exception, the connection would still be accepted. If a user relies on this callback for any security-sensitive behavior (such as server name-based access control or certificate validation), this vulnerability could allow the security mechanism to be bypassed, potentially permitting unauthorized connections or access.(CVE-2026-27448)</p>
<p>pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.(CVE-2026-27459)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10392-1</id>
    <title>openSUSE-SU-2026:10392-1 — python311-pyOpenSSL-26.0.0-1.1 on GA media</title>
    <updated>2026-10-03T12:32:18.758749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-pyOpenSSL-26.0.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10392-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2268</id>
    <title>PYSEC-2026-2268</title>
    <updated>2026-10-03T12:32:18.758766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pyopenssl</p>
<p>pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:7224</id>
    <title>RHSA-2026:7224 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T12:32:18.758784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pyOpenSSL: TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback pyOpenSSL: DTLS cookie callback buffer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:7224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-2255</id>
    <title>SUSE-EL-9-CLIENT-TOOLS-2026-2255 — Security update 5.0.8 for Multi-Linux Manager Salt Bundle</title>
    <updated>2026-10-03T12:32:18.758801+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 5.0.8 for Multi-Linux Manager Salt Bundle</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-2255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27448</id>
    <title>UBUNTU-CVE-2026-27448</title>
    <updated>2026-10-03T12:32:18.758815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: pyopenssl, Ubuntu:Pro:18.04:LTS: pyopenssl, Ubuntu:Pro:20.04:LTS: pyopenssl, Ubuntu:22.04:LTS: pyopenssl, Ubuntu:24.04:LTS: pyopenssl, Ubuntu:25.10: pyopenssl</p>
<p>pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1183</id>
    <title>WID-SEC-W-2026-1183 — Red Hat Hardened Images RPMs (jq und pyOpenSSL): Mehrere Schwachstellen</title>
    <updated>2026-10-03T12:32:18.758841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Red Hat Hardened Images RPMs ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial-of-Service-Zustand verursachen, vertrauliche Informationen offenlegen oder nicht näher spezifizierte Angriffe durchführen, einschließlich potenzieller Codeausführung.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1183"/>
  </entry>
</feed>
