pyOpenSSL DTLS cookie callback buffer overflow
Description
Published to the GitHub Advisory Database
Mar 16, 2026
Reviewed
Mar 16, 2026
Published by the National Vulnerability Database
Mar 18, 2026
Last updated
Mar 19, 2026
If a user provided callback to
set_cookie_generate_callbackreturned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer.Cookie values that are too long are now rejected.
References