Cyber Resilience

CVE-2026-27448

Pyopenssl 0.14 – 26.0.0

Published
18 March 2026
Modified
23 March 2026
Patch / advisory
CVSS Score v4 1.7
Click a component to see what it means
Raw vectorCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0024 15th percentile
Risk Priority 22 floored blend · peak EPSS

Summary

CVE-2026-27448 is a low-severity Failing Open (CWE-636) vulnerability in Pyopenssl Pyopenssl. Its CVSS base score is 1.7 (Low).

Operationally, ranked at the 15th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to CP-12 (Safe Mode) and SC-24 (Fail in Known State) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user…

more

was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-27459Same product: Pyopenssl Pyopenssl
CVE-2026-40525Shared CWE-636
CVE-2026-53852Shared CWE-636
CVE-2026-53837Shared CWE-636
CVE-2026-69306Shared CWE-636
CVE-2025-21210Shared CWE-636
CVE-2023-4030Shared CWE-636
CVE-2026-42423Shared CWE-636
CVE-2026-22034Shared CWE-636
CVE-2026-41334Shared CWE-636

Affected Assets

pyopenssl
pyopenssl
0.14 — 26.0.0

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V3.2.1
  • V7.4.1
  • V8.3.3
  • V10.3.4

Mitigating Controls (NIST 800-53 r5) AI

SC-24 directly requires the system to fail to a known state that preserves security properties, structurally stopping fallback to a less-secure mode.

SI-17 mandates explicit fail-safe procedures that activate on indicated failures, preventing the insecure fallback behavior.

CP-12 forces entry into a safe mode on detected conditions, limiting exposure but not covering every failure path.

SA-8 requires application of engineering principles that include fail-secure design, reducing the likelihood the weakness is introduced.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure-development practices explicitly include designing error and failure handling to remain in a secure state.

PR.AA-05 partial match
prevents

Least-privilege policy and enforcement directly counters the permissive-access fallback example in the CWE.

PR.PS-01 partial match
prevents

Hardened baselines and configuration management reduce the chance that error paths default to insecure settings.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

none

The control forces an explicit evaluation step before any response, reducing the chance that a failure condition will default to an unsafe open state.

References