CVE-2026-27459
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update
Beschreibung
pyOpenSSL ist eine Python-Schnittstelle für die OpenSSL-Bibliothek. Ab Version 22.0.0 und bis einschließlich Version 25.999.999 überschrieb pyOpenSSL einen von OpenSSL bereitgestellten Puffer, wenn ein vom Benutzer bereitgestelltes Callback zur `set_cookie_generate_callback` eine Cookie-Wertgröße größer als 256 Bytes zurückgab. Ab Version 26.0.0 werden nun zu lange Cookie-Werte abgelehnt.
Metriken
Weakness-Klassen (CWE)
CWE-120Base
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-09-10 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/27xxx/CVE-2026-27459.json">CVE-2026-27459</a>
- CVE Modified2026-08-31 13:17 UTC· security-advisories@github.com
- Reference: https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst
- Reference: https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408
- Reference: https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4
- Reference: https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst
- CVE Modified2026-08-31 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/27xxx/CVE-2026-27459.json">CVE-2026-27459</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:10754
- Reference: https://access.redhat.com/errata/RHSA-2026:11856
- Reference: https://access.redhat.com/errata/RHSA-2026:11916
- CVE Modified2026-08-25 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:59153
- Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+91) → Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+93)
- CVE Modified2026-08-20 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+91) → Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+91)
Betroffene Betriebssysteme
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
ubuntu / pyasn1jammy
linux
ubuntu / pyasn1noble
linux
ubuntu / pyasn1resolute
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
Atlassian
BambooData Center LTS 10.2.22
Atlassian
BambooData Center LTS 12.1.10
Atlassian
BitbucketData Center 10.4.2
Atlassian
BitbucketData Center LTS 10.2.6
Atlassian
BitbucketData Center LTS 9.4.23
Atlassian
ConfluenceData Center LTS 10.2.15
Atlassian
ConfluenceData Center LTS 9.2.23
Atlassian
Crucible4.9.13
Atlassian
Fisheye4.9.13
Atlassian
JiraData Center LTS 10.3.24
Atlassian
JiraData Center LTS 11.3.10
bitnami
django6.0.0
djangoproject
daphne4.2.2
js-cookie
javascript_cookie3.0.7
npm
tmp
npm
webpack-dev-server
pyopenssl
pyopenssl22.0.0 – 26.0.0
pypi
aiohttp0.1
pypi
aiohttp0.10.0
pypi
aiohttp0.10.1
pypi
aiohttp0.10.2
pypi
aiohttp0.11.0
pypi
aiohttp0.12.0
pypi
aiohttp0.13.0
Quellen & Referenzen
- https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6rweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-59886advisory
- https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886web
- https://github.com/pyasn1/pyasn1package
- https://github.com/pyasn1/pyasn1/releases/tag/v0.6.4web
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22vweb
- https://github.com/aio-libs/aiohttp/pull/13017web
- https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98web
- https://github.com/aio-libs/aiohttppackage
- https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2web
- https://pypi.org/project/aiohttppackage
- https://github.com/advisories/GHSA-mfx4-hv73-q22vadvisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-69243advisory
- https://github.com/vitejs/vite/security/advisories/GHSA-p9ff-h696-f583web
- https://nvd.nist.gov/vuln/detail/CVE-2026-39363advisory
- https://github.com/vitejs/vite/pull/22159web
- https://github.com/vitejs/vite/commit/f02d9fde0b195afe3ea2944414186962fbbe41e0web
- https://github.com/vitejs/vitepackage
- https://github.com/vitejs/vite/releases/tag/v6.4.2web
- https://github.com/vitejs/vite/releases/tag/v7.3.2web
Verknüpfte CVEs
- CVE-2026-9595
Ein Fehler wurde im webpack-dev-server gefunden.
mediumCVSSv3 5.3 - CVE-2026-71366
Ein Server-seitiger Anfrage-Fälschungsangriff (SSRF) wurde in mehreren AWX-Benachrichtigungshintergründen gefunden.
highCVSSv3 7.7 - CVE-2026-71365
Ein Server-seitiger Anfrage-Fälschungsangriff (SSRF) wurde im Webhook-Status-Rückrufmechanismus von AWX gefunden.
highCVSSv3 7.7 - CVE-2026-71364
Ein Pfad-Traversierungs-Schwachstellen wurde in der Projektarchiv-Extraktion von AWX gefunden.
highCVSSv3 7.2 - CVE-2026-69244
AIOHTTP ist ein asynchroner HTTP-Client/Server-Framework für asyncio und Python.
high - CVE-2026-69243
AIOHTTP ist ein asynchroner HTTP-Client/Server-Framework für asyncio und Python.
medium - CVE-2026-59886
pyasn1 ist eine generische ASN.1-Bibliothek für Python.
highCVSSv3 7.5 - CVE-2026-46625
JavaScript-Cookie ist eine JavaScript-API zum Umgang mit Cookies auf der Client-Seite.
highCVSSv3 7.5 - CVE-2026-44705
tmp ist ein Erzeuger für temporäre Dateien und Verzeichnisse für Node.js.
high - CVE-2026-44545
Daphne vor Version 4.2.2 übertrug die Werte für maxFramePayloadSize und maxMessagePayloadSize nicht an Autobahns WebSocketServerFactory.
highCVSSv3 7.5 - CVE-2026-44244
GitPython ist eine Python-Bibliothek zum Interagieren mit Git-Repositorys.
highCVSSv3 7.8 - CVE-2026-39363
Vite ist ein Frontend-Tooling-Framework für JavaScript.
highCVSSv3 7.5 - CVE-2026-15307
Ein Problem wurde in Django-Versionen vor 5.2.17 und 6.0 vor 6.0.8 entdeckt.
highCVSSv3 8.8 - CVE-2026-12143
Die Bibliothek `form-data` dient zum Erstellen von lesbaren Multipart/form-data-Streams.
highCVSSv3 7.5