{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-27448",
        "tracking": {
            "current_release_date": "2026-03-24T10:15:43.634003Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-27448",
            "initial_release_date": "2026-03-16T16:03:33.953933Z",
            "revision_history": [
                {
                    "date": "2026-03-16T16:03:33.953933Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-16T16:03:42.721096Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-17T23:38:32.683870Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-17T23:38:38.186361Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-18T00:25:12.801326Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-18T00:25:17.046212Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-18T12:44:33.218080Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products created (2)."
                },
                {
                    "date": "2026-03-18T16:02:12.076275Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-18T20:38:52.032851Z",
                    "number": "9",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-19T00:28:18.899275Z",
                    "number": "10",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (46).| Product Identifiers created (13).| Product Remediations created (46).| References created (5).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-19T00:28:34.088502Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T12:20:05.124138Z",
                    "number": "12",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:28:34.456311Z",
                    "number": "13",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:28:37.950810Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:41:05.642753Z",
                    "number": "15",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T18:22:02.002691Z",
                    "number": "16",
                    "summary": "Products created (2).| Product Identifiers created (2)."
                },
                {
                    "date": "2026-03-20T19:56:18.620395Z",
                    "number": "17",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-21T12:19:58.561126Z",
                    "number": "18",
                    "summary": "Product Remediations created (1)."
                },
                {
                    "date": "2026-03-21T12:20:02.820235Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T10:15:34.713805Z",
                    "number": "20",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| Product Identifiers created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T10:15:40.990045Z",
                    "number": "21",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "21"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1508257",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-3023480",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_core:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Ansible Automation Platform Ansible Core 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/6",
                                "product": {
                                    "name": "vers:rpm/6",
                                    "product_id": "CSAFPID-1439321",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:6"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 6"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439315",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439279",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_ai"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1439328",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift Container Platform 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/17.1",
                                "product": {
                                    "name": "vers:rpm/17.1",
                                    "product_id": "CSAFPID-1441193",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openstack:17.1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenStack Platform 17.1"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/18.0",
                                "product": {
                                    "name": "vers:rpm/18.0",
                                    "product_id": "CSAFPID-1441197",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openstack:18.0"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenStack Platform 18.0"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-1441200",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:quay:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Quay 3"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/6",
                                "product": {
                                    "name": "vers:rpm/6",
                                    "product_id": "CSAFPID-1439313",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:satellite:6"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Satellite 6"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1441204",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Trusted Artifact Signer"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1771989",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:rhui:4::el8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Update Infrastructure 4 for Cloud Providers"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5008757"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ansible-dev-tools-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1508264"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-controller"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5172458"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5172459"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "eda-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2698058"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-minimal-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2698059"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-supported-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2518221"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-supported-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5172461"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "hub-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1508261"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "lightspeed-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5009266"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "lightspeed-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5008758"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "platform-resource-runner-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846029"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python-pyOpenSSL"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846025"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python3.11-pyOpenSSL"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846026"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python3.12-pyOpenSSL"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846027"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python3x-pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3093049"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-minimal-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-4534157"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-minimal-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Ansible Automation Platform Ansible Core 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2855768"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "iop-advisor-engine-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5276235"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "iop-insights-engine-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846040"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python-pyOpenSSL"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846039"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python3.12-pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Satellite 6"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5119831"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "model-transparency-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Trusted Artifact Signer"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2976378"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-feature-server-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5811359"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-mlflow-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846030"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 6"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846032"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846033"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846035"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Container Platform 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846036"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenStack Platform 17.1"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846037"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenStack Platform 18.0"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846041"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python-pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Update Infrastructure 4 for Cloud Providers"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1455906"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "quay-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5355695"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "quay-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Quay 3"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/*",
                                        "product": {
                                            "name": "vers:microsoft/*",
                                            "product_id": "CSAFPID-5874051",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:azl3_pyopenssl_24.2.1-1:*:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "azl3 pyOpenSSL 24.2.1-1 on Azure Linux 3.0"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/*",
                                        "product": {
                                            "name": "vers:microsoft/*",
                                            "product_id": "CSAFPID-5874052",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:cbl2_pyopenssl_18.0.0-8:*:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cbl2 pyOpenSSL 18.0.0-8 on CBL Mariner 2.0"
                            }
                        ],
                        "category": "product_family",
                        "name": "Open Source Software"
                    }
                ],
                "category": "vendor",
                "name": "Microsoft"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0.14|<26.0.0",
                                "product": {
                                    "name": "vers:unknown/>=0.14|<26.0.0",
                                    "product_id": "CSAFPID-5897407",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:pyopenssl:pyopenssl:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "pyOpenSSL"
                    }
                ],
                "category": "vendor",
                "name": "pyOpenSSL"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-5843889"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyopenssl"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-5843890"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyopenssl"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0.14.0|<26.0.0",
                                "product": {
                                    "name": "vers:unknown/>=0.14.0|<26.0.0",
                                    "product_id": "CSAFPID-5839522"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "pyopenssl"
                    }
                ],
                "category": "vendor",
                "name": "pyca"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-27448",
            "cwe": {
                "id": "CWE-636",
                "name": "Not Failing Securely ('Failing Open')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "If a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it.\n\nUnhandled exceptions now result in rejecting the connection.\n\nCredit to **Leury Castillo** for reporting this issue.",
                    "title": "github - https://github.com/advisories/GHSA-vp96-hxj8-p424"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-27448"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-27448"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-27448"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in pyOpenSSL. The set_tlsext_servername_callback callback function can be used to implement Server Name Indication (SNI) during the TLS handshake. When the callback raises an unhandled exception, the handshake incorrectly proceeds instead of terminating. This fail-open behavior can allow an attacker to bypass SNI-based security controls and access restricted endpoints.\nThis flaw is only exploitable when an application using the pyOpenSSL library provides a custom callback to the set_tlsext_servername_callback function. For the handshake to proceed incorrectly, the callback must raise an unhandled exception, limiting the exposure of this issue. Due to these reasons, this vulnerability has been rated with an important severity.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-27448"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL allows TLS connection bypass via unhandled callback exception in set\\_tlsext\\_servername\\_callback",
                    "title": "microsoft - https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Mar"
                },
                {
                    "category": "description",
                    "text": "If a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it.\n\nUnhandled exceptions now result in rejecting the connection.\n\nCredit to **Leury Castillo** for reporting this issue.",
                    "title": "github - https://api.github.com/advisories/GHSA-vp96-hxj8-p424"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback for any security-sensitive behavior, this could allow bypassing it. Starting in version 26.0.0, unhandled exceptions now result in rejecting the connection.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27448"
                },
                {
                    "category": "other",
                    "text": "0.0004",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "1.7",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.4",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product, VENDOR FIX as product remediation category",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent CVSS (V3) score, Is related to a product by vendor Red Hat, There is product_remediation data available from source Redhat",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5839522",
                    "CSAFPID-5843889",
                    "CSAFPID-5843890",
                    "CSAFPID-1439279",
                    "CSAFPID-1439313",
                    "CSAFPID-1439317",
                    "CSAFPID-1439328",
                    "CSAFPID-1441193",
                    "CSAFPID-1441197",
                    "CSAFPID-1441200",
                    "CSAFPID-1441204",
                    "CSAFPID-1455906",
                    "CSAFPID-1508257",
                    "CSAFPID-1508261",
                    "CSAFPID-1508264",
                    "CSAFPID-1771989",
                    "CSAFPID-2518221",
                    "CSAFPID-2698058",
                    "CSAFPID-2698059",
                    "CSAFPID-2855768",
                    "CSAFPID-2976378",
                    "CSAFPID-3023480",
                    "CSAFPID-3093049",
                    "CSAFPID-4534157",
                    "CSAFPID-5008757",
                    "CSAFPID-5008758",
                    "CSAFPID-5009266",
                    "CSAFPID-5119831",
                    "CSAFPID-5172458",
                    "CSAFPID-5172459",
                    "CSAFPID-5172461",
                    "CSAFPID-5276235",
                    "CSAFPID-5355695",
                    "CSAFPID-5811359",
                    "CSAFPID-5846025",
                    "CSAFPID-5846026",
                    "CSAFPID-5846027",
                    "CSAFPID-5846029",
                    "CSAFPID-5846033",
                    "CSAFPID-5846035",
                    "CSAFPID-5846036",
                    "CSAFPID-5846037",
                    "CSAFPID-5846039",
                    "CSAFPID-5846040",
                    "CSAFPID-5846041",
                    "CSAFPID-5874051",
                    "CSAFPID-5874052",
                    "CSAFPID-5897407"
                ],
                "known_not_affected": [
                    "CSAFPID-1439315",
                    "CSAFPID-1439321",
                    "CSAFPID-5846030",
                    "CSAFPID-5846032"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-vp96-hxj8-p424"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-vp96-hxj8-p424"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-27448"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/27xxx/CVE-2026-27448.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27448"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27448"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-27448"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-27448"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-27448"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-27448.json"
                },
                {
                    "category": "external",
                    "summary": "Source - microsoft",
                    "url": "https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Mar"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-vp96-hxj8-p424"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27448"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://github.com/pyca/pyopenssl/security/advisories/GHSA-vp96-hxj8-p424"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://github.com/pyca/pyopenssl/commit/d41a814759a9fb49584ca8ab3f7295de49a85aa0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst#L27"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-vp96-hxj8-p424"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-27448"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27448"
                }
            ],
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "To mitigate this flaw, ensure the callback provided to the set_tlsext_servername_callback function is wrapped in a try/except block. This block should explicitly return a failure code instead of allowing the exception to propagate.",
                    "product_ids": [
                        "CSAFPID-1439279",
                        "CSAFPID-1439313",
                        "CSAFPID-1439315",
                        "CSAFPID-1439317",
                        "CSAFPID-1439321",
                        "CSAFPID-1439328",
                        "CSAFPID-1441193",
                        "CSAFPID-1441197",
                        "CSAFPID-1441200",
                        "CSAFPID-1441204",
                        "CSAFPID-1455906",
                        "CSAFPID-1508257",
                        "CSAFPID-1508261",
                        "CSAFPID-1508264",
                        "CSAFPID-1771989",
                        "CSAFPID-2518221",
                        "CSAFPID-2698058",
                        "CSAFPID-2698059",
                        "CSAFPID-2855768",
                        "CSAFPID-2976378",
                        "CSAFPID-3023480",
                        "CSAFPID-3093049",
                        "CSAFPID-4534157",
                        "CSAFPID-5008757",
                        "CSAFPID-5008758",
                        "CSAFPID-5009266",
                        "CSAFPID-5119831",
                        "CSAFPID-5172458",
                        "CSAFPID-5172459",
                        "CSAFPID-5172461",
                        "CSAFPID-5276235",
                        "CSAFPID-5355695",
                        "CSAFPID-5811359",
                        "CSAFPID-5846025",
                        "CSAFPID-5846026",
                        "CSAFPID-5846027",
                        "CSAFPID-5846029",
                        "CSAFPID-5846030",
                        "CSAFPID-5846032",
                        "CSAFPID-5846033",
                        "CSAFPID-5846035",
                        "CSAFPID-5846036",
                        "CSAFPID-5846037",
                        "CSAFPID-5846039",
                        "CSAFPID-5846040",
                        "CSAFPID-5846041"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "CBL-Mariner Releases",
                    "product_ids": [
                        "CSAFPID-5874051"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1439279",
                        "CSAFPID-1439313",
                        "CSAFPID-1439317",
                        "CSAFPID-1439328",
                        "CSAFPID-1441193",
                        "CSAFPID-1441197",
                        "CSAFPID-1441200",
                        "CSAFPID-1441204",
                        "CSAFPID-1455906",
                        "CSAFPID-1508257",
                        "CSAFPID-1508261",
                        "CSAFPID-1508264",
                        "CSAFPID-1771989",
                        "CSAFPID-2518221",
                        "CSAFPID-2698058",
                        "CSAFPID-2698059",
                        "CSAFPID-2855768",
                        "CSAFPID-2976378",
                        "CSAFPID-3023480",
                        "CSAFPID-3093049",
                        "CSAFPID-4534157",
                        "CSAFPID-5008757",
                        "CSAFPID-5008758",
                        "CSAFPID-5009266",
                        "CSAFPID-5119831",
                        "CSAFPID-5172458",
                        "CSAFPID-5172459",
                        "CSAFPID-5172461",
                        "CSAFPID-5276235",
                        "CSAFPID-5355695",
                        "CSAFPID-5811359",
                        "CSAFPID-5839522",
                        "CSAFPID-5843889",
                        "CSAFPID-5843890",
                        "CSAFPID-5846025",
                        "CSAFPID-5846026",
                        "CSAFPID-5846027",
                        "CSAFPID-5846029",
                        "CSAFPID-5846033",
                        "CSAFPID-5846035",
                        "CSAFPID-5846036",
                        "CSAFPID-5846037",
                        "CSAFPID-5846039",
                        "CSAFPID-5846040",
                        "CSAFPID-5846041",
                        "CSAFPID-5874051",
                        "CSAFPID-5874052",
                        "CSAFPID-5897407"
                    ]
                }
            ],
            "title": "CVE-2026-27448"
        }
    ]
}