CVE-2026-27459

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update

criticalEPSS 0.7 %

Beschreibung

pyOpenSSL ist eine Python-Schnittstelle für die OpenSSL-Bibliothek. Ab Version 22.0.0 und bis einschließlich Version 25.999.999 überschrieb pyOpenSSL einen von OpenSSL bereitgestellten Puffer, wenn ein vom Benutzer bereitgestelltes Callback zur `set_cookie_generate_callback` eine Cookie-Wertgröße größer als 256 Bytes zurückgab. Ab Version 26.0.0 werden nun zu lange Cookie-Werte abgelehnt.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.8
Quelle: nvd-v3
51.2 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.7 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-24 17:56 UTC
CWE-120

Weakness-Klassen (CWE)

  • CWE-120Base

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

    The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-10 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/27xxx/CVE-2026-27459.json">CVE-2026-27459</a>
  2. CVE Modified2026-08-31 13:17 UTC· security-advisories@github.com
    • Reference: https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst
    • Reference: https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408
    • Reference: https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4
    • Reference: https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst
  3. CVE Modified2026-08-31 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/27xxx/CVE-2026-27459.json">CVE-2026-27459</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:10754
    • Reference: https://access.redhat.com/errata/RHSA-2026:11856
    • Reference: https://access.redhat.com/errata/RHSA-2026:11916
  4. CVE Modified2026-08-25 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:59153
    • Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+91)Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+93)
  5. CVE Modified2026-08-20 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+91)Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+91)

Betroffene Betriebssysteme

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / pyasn1jammy

  • linux

    ubuntu / pyasn1noble

  • linux

    ubuntu / pyasn1resolute

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    django6.0.0

  • djangoproject

    daphne4.2.2

  • js-cookie

    javascript_cookie3.0.7

  • npm

    tmp

  • npm

    webpack-dev-server

  • pyopenssl

    pyopenssl22.0.0 – 26.0.0

  • pypi

    aiohttp0.1

  • pypi

    aiohttp0.10.0

  • pypi

    aiohttp0.10.1

  • pypi

    aiohttp0.10.2

  • pypi

    aiohttp0.11.0

  • pypi

    aiohttp0.12.0

  • pypi

    aiohttp0.13.0

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-27459