Description
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to set_tlsext_servername_callback raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 pypi | | | 26.0.0 |
 debian 11 | | =20.0.1-1 || =21.0.0-1 || =22.1.0+really21.0.0-1 || =22.1.0-1 || =23.0.0-1 || =23.2.0-1 || =24.0.0-1 || =24.0.0-2 || =24.0.0-3 || =24.0.0-4 || =24.0.0-5 || =24.1.0-1 || =24.2.1-1 || =24.3.0-1 || =25.0.0-1 || =25.1.0-1 || =25.1.0-2 || =25.3.0-1 || =25.3.0-2 || =26.0.0-1 || =26.1.0-1 || =26.2.0-1 || =26.2.0-1~exp1 || =26.3.0-1~exp1 | - |
 debian 12 | | =23.0.0-1 || =23.2.0-1 || =24.0.0-1 || =24.0.0-2 || =24.0.0-3 || =24.0.0-4 || =24.0.0-5 || =24.1.0-1 || =24.2.1-1 || =24.3.0-1 || =25.0.0-1 || =25.1.0-1 || =25.1.0-2 || =25.3.0-1 || =25.3.0-2 || =26.0.0-1 || =26.1.0-1 || =26.2.0-1 || =26.2.0-1~exp1 || =26.3.0-1~exp1 | - |
 debian 13 | | =25.0.0-1 || >=0 <25.0.0-1+deb13u1 | 25.0.0-1+deb13u1 |
 debian 14 | | =25.0.0-1 || =25.1.0-1 || =25.1.0-2 || =25.3.0-1 || =25.3.0-2 || >=0 <26.0.0-1 | 26.0.0-1 |
 rpm rhel8 | | - | - |