CVE-2026-27448
MediumAdvisory
Published 16 Mar 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.3
- base score, highest
- EPSS
- 0.002
- 15th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 305
- of 17,781 indexed, latest versions
- Container images
- 186
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
Carried by container images the latest versions of 305 of 17,781 indexed charts deploy, on 186 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pyopensslpypi | 16.2.0, 17.3.0, 17.5.0, 18.0.0+18 more | 26.0.0 | 186 |
| pyopenssldeb | 17.5.0-1ubuntu1, 23.2.0-1 | 17.5.0-1ubuntu1+esm1, 23.2.0-1ubuntu0.1 | 4 |
- OSV records
- GHSA-vp96-hxj8-p424UBUNTU-CVE-2026-27448
- Also known as
- PYSEC-2026-2268, USN-8115-1, USN-8335-1
Charts affected
305 by stars
Container images carrying it
186 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 7dcddc01f13b | pyopenssl | 26.0.0 | 89 |
| library/ | 4bc6bc963e6d | pyopenssl | 26.0.0 | 22 |
| library/ | b3b90af2a655 | pyopenssl | 26.0.0 | 16 |
| library/ | 257388edf9c8 | pyopenssl | 26.0.0 | 6 |
| apache/ | 16b50bbef664 | pyopenssl | 26.0.0 | 3 |
| mysql/ | d6c8301b7834 | pyopenssl | 26.0.0 | 3 |
| amancevice/ | 12a0a9e66550 | pyopenssl | 26.0.0 | 2 |
| cs3org/ | 02a9e78757b4 | pyopenssl | 26.0.0 | 2 |
| larribas/ | 05ccb0b46bfb | pyopenssl | 26.0.0 | 2 |
| library/ | 212fe73edca5 | pyopenssl | 26.0.0 | 2 |
| library/ | ac80b6e09e5b | pyopenssl | 26.0.0 | 2 |
| library/ | b2cf29815e62 | pyopenssl | 26.0.0 | 2 |
| lncm/ | 36eaa06f99f4 | pyopenssl | 26.0.0 | 2 |
| ngoduykhanh/ | ba36ab196d3d | pyopenssl | 26.0.0 | 2 |
| omecproject/ | cfdb566dd949 | pyopenssl | 26.0.0 | 2 |
| ghcr.io/ | 33e60bfb40f2 | pyopenssl | 26.0.0 | 2 |
| quay.io/ | 0b62db8afc9b | pyopenssl | 26.0.0 | 2 |
| quay.io/ | f7f8228f17cc | pyopenssl | 26.0.0 | 2 |
| alerta/ | 4786b9eaa606 | pyopenssl | 26.0.0 | 1 |
| amd64/ | e20a653e0f51 | pyopenssl | 26.0.0 | 1 |
| anchore/ | bde9eedf639d | pyopenssl | 26.0.0 | 1 |
| anchore/ | ed9b3badd17c | pyopenssl | 26.0.0 | 1 |
| apache/ | 64e58748b6b9 | pyopenssl | 26.0.0 | 1 |
| apache/ | ce90bdc3d2af | pyopenssl | 26.0.0 | 1 |
| apache/ | e5560ad0b86e | pyopenssl | 26.0.0 | 1 |
| appwrite/ | 1aaa70127114 | pyopenssl | 26.0.0 | 1 |
| aristidetm/ | 469dbc951224 | pyopenssl | 26.0.0 | 1 |
| aristidetm/ | ccb516cb8474 | pyopenssl | 26.0.0 | 1 |
| assistiot/ | c3adbab6a3e7 | pyopenssl | 26.0.0 | 1 |
| baserow/ | e0b3c8130b91 | pyopenssl | 26.0.0 | 1 |
| baserow/ | df0c42eb67e8 | pyopenssl | 26.0.0 | 1 |
| benbusby/ | f77f7e6e4ad2 | pyopenssl | 26.0.0 | 1 |
| berkeleyskypilot/ | 8da2f3cda472 | pyopenssl | 26.0.0 | 1 |
| bnjbvr/ | 37e216b182c8 | pyopenssl | 26.0.0 | 1 |
| cloudve/ | d79c1c5881c0 | pyopenssl | 26.0.0 | 1 |
| copyparty/ | 0a0a8605062c | pyopenssl | 26.0.0 | 1 |
| dannielkil/ | 433290c5c1db | pyopenssl | 26.0.0 | 1 |
| daskdev/ | 4ecd7bc35500 | pyopenssl | 26.0.0 | 1 |
| daskdev/ | 052630f5ca04 | pyopenssl | 26.0.0 | 1 |
| datamate/ | 2dd66b722464 | pyopenssl | 26.0.0 | 1 |
| ddosify/ | a43c5155fa1c | pyopenssl | 26.0.0 | 1 |
| ddosify/ | e5be48b37348 | pyopenssl | 26.0.0 | 1 |
| ddosify/ | 3c11e3182652 | pyopenssl | 26.0.0 | 1 |
| ddosify/ | ac323d52bfb4 | pyopenssl | 26.0.0 | 1 |
| deconzcommunity/ | 6541bbb78952 | pyopenssl | 26.0.0 | 1 |
| deepflowce/ | 3d7ae561cf60 | pyopenssl | 26.0.0 | 1 |
| devopstales/ | 8bb837da5aec | pyopenssl | 26.0.0 | 1 |
| devopstales/ | 75136aa7a26e | pyopenssl | 26.0.0 | 1 |
| douz/ | 4384103d0219 | pyopenssl | 26.0.0 | 1 |
| dysnix/ | 19951e3e7a32 | pyopenssl | 26.0.0 | 1 |