Description
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
Problem types
CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
References
github.com/...penssl/security/advisories/GHSA-5pwr-322w-8jr4
github.com/...ommit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408
github.com/...c4e364c59930e53a270116249581eaa3/CHANGELOG.rst