{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-27459",
        "tracking": {
            "current_release_date": "2026-03-27T21:41:15.992445Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-27459",
            "initial_release_date": "2026-03-16T16:43:01.092504Z",
            "revision_history": [
                {
                    "date": "2026-03-16T16:43:01.092504Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-16T16:43:03.279367Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-17T23:38:33.840919Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-17T23:38:38.186361Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-18T00:25:23.331218Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-18T00:25:28.367389Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-18T12:44:33.753821Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products connected (2)."
                },
                {
                    "date": "2026-03-18T12:44:35.872826Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-18T16:02:11.284918Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-18T20:38:47.296408Z",
                    "number": "10",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-19T00:28:04.690713Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (33).| Product Identifiers created (13).| Product Remediations created (46).| Products created (13).| References created (5).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-03-19T00:28:21.144714Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-19T12:20:06.302899Z",
                    "number": "13",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:31:26.924100Z",
                    "number": "14",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:31:29.957638Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:41:02.684372Z",
                    "number": "16",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T18:22:02.716951Z",
                    "number": "17",
                    "summary": "Products connected (2)."
                },
                {
                    "date": "2026-03-20T19:56:09.268596Z",
                    "number": "18",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-03-21T12:19:58.957780Z",
                    "number": "19",
                    "summary": "Product Remediations created (1)."
                },
                {
                    "date": "2026-03-21T12:20:02.820235Z",
                    "number": "20",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-24T10:15:33.654377Z",
                    "number": "21",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| Product Identifiers created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-03-24T10:15:40.990045Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-25T17:25:18.125263Z",
                    "number": "23",
                    "summary": "Products created (1).| Product Identifiers created (1).| Products removed (1)."
                },
                {
                    "date": "2026-03-25T17:25:24.748406Z",
                    "number": "24",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-27T21:40:55.046060Z",
                    "number": "25",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "25"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-1508257",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_automation_platform:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/2",
                                "product": {
                                    "name": "vers:rpm/2",
                                    "product_id": "CSAFPID-3023480",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:ansible_core:2"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Ansible Automation Platform Ansible Core 2"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/6",
                                "product": {
                                    "name": "vers:rpm/6",
                                    "product_id": "CSAFPID-1439321",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:6"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 6"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/7",
                                "product": {
                                    "name": "vers:rpm/7",
                                    "product_id": "CSAFPID-1439315",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:7"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/8",
                                "product": {
                                    "name": "vers:rpm/8",
                                    "product_id": "CSAFPID-1439317",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:enterprise_linux:8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/unknown",
                                "product": {
                                    "name": "vers:rpm/unknown",
                                    "product_id": "CSAFPID-1439279",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift_ai"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1439328",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openshift:4"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenShift Container Platform 4"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/17.1",
                                "product": {
                                    "name": "vers:rpm/17.1",
                                    "product_id": "CSAFPID-1441193",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openstack:17.1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenStack Platform 17.1"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/18.0",
                                "product": {
                                    "name": "vers:rpm/18.0",
                                    "product_id": "CSAFPID-1441197",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:openstack:18.0"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat OpenStack Platform 18.0"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/3",
                                "product": {
                                    "name": "vers:rpm/3",
                                    "product_id": "CSAFPID-1441200",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:quay:3"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Quay 3"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/6",
                                "product": {
                                    "name": "vers:rpm/6",
                                    "product_id": "CSAFPID-1439313",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:satellite:6"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Satellite 6"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-1441204",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:trusted_artifact_signer:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Trusted Artifact Signer"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/4",
                                "product": {
                                    "name": "vers:rpm/4",
                                    "product_id": "CSAFPID-1771989",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:rhui:4::el8"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Update Infrastructure 4 for Cloud Providers"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5008757"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ansible-dev-tools-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1508264"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "automation-controller"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5172458"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5172459"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "eda-controller-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2698058"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-minimal-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2698059"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-supported-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2518221"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-supported-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5172461"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "hub-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1508261"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "lightspeed-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5009266"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "lightspeed-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5008758"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "platform-resource-runner-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846029"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python-pyOpenSSL"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846025"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python3.11-pyOpenSSL"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846026"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python3.12-pyOpenSSL"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846027"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python3x-pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Ansible Automation Platform 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-3093049"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-minimal-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-4534157"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "ee-minimal-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Ansible Automation Platform Ansible Core 2"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2855768"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "iop-advisor-engine-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5276235"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "iop-insights-engine-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846040"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python-pyOpenSSL"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846039"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python3.12-pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Satellite 6"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5119831"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "model-transparency-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Trusted Artifact Signer"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-2976378"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-feature-server-rhel9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5811359"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "odh-mlflow-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift AI (RHOAI)"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846030"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 6"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846032"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846033"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Enterprise Linux 8"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846035"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenShift Container Platform 4"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846036"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenStack Platform 17.1"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846037"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat OpenStack Platform 18.0"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5846041"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "python-pyOpenSSL"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Update Infrastructure 4 for Cloud Providers"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-1455906"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "quay-rhel8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-5355695"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "quay-rhel9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Quay 3"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/*",
                                        "product": {
                                            "name": "vers:microsoft/*",
                                            "product_id": "CSAFPID-5874051",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:azl3_pyopenssl_24.2.1-1:*:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "azl3 pyOpenSSL 24.2.1-1 on Azure Linux 3.0"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:microsoft/*",
                                        "product": {
                                            "name": "vers:microsoft/*",
                                            "product_id": "CSAFPID-5874052",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:microsoft:cbl2_pyopenssl_18.0.0-8:*:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "cbl2 pyOpenSSL 18.0.0-8 on CBL Mariner 2.0"
                            }
                        ],
                        "category": "product_family",
                        "name": "Open Source Software"
                    }
                ],
                "category": "vendor",
                "name": "Microsoft"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=22.0.0|<26.0.0",
                                "product": {
                                    "name": "vers:unknown/>=22.0.0|<26.0.0",
                                    "product_id": "CSAFPID-5906992",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:pyopenssl:pyopenssl:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "pyOpenSSL"
                    }
                ],
                "category": "vendor",
                "name": "pyOpenSSL"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-5843889"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyopenssl"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-5843890"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "pyopenssl"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=22.0.0|<26.0.0",
                                "product": {
                                    "name": "vers:unknown/>=22.0.0|<26.0.0",
                                    "product_id": "CSAFPID-5839524"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "pyopenssl"
                    }
                ],
                "category": "vendor",
                "name": "pyca"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-27459",
            "cwe": {
                "id": "CWE-120",
                "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "If a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer.\n\nCookie values that are too long are now rejected.",
                    "title": "github - https://api.github.com/advisories/GHSA-5pwr-322w-8jr4"
                },
                {
                    "category": "description",
                    "text": "If a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer.\n\nCookie values that are too long are now rejected.",
                    "title": "github - https://github.com/advisories/GHSA-5pwr-322w-8jr4"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-27459"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-27459"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL DTLS cookie callback buffer overflow",
                    "title": "microsoft - https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Mar"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-27459"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in pyOpenSSL. The set_cookie_generate_callback callback function can be used to generate DTLS cookies. When the callback returns a cookie string or byte sequence longer than 256 bytes, a buffer overflow can be triggered due to a missing bounds checking before copying the data to a fixed-size buffer provided by the underlying OpenSSL library.\nThis flaw is only exploitable when an application using the pyOpenSSL library provides a custom callback to the set_cookie_generate_callback function. For the buffer overflow to occur, the callback function must return a cookie string or byte sequence longer than 256 bytes, limiting the exposure of this issue. Due to these reasons, this vulnerability has been rated with an important severity.",
                    "title": "redhat - https://access.redhat.com/security/cve/CVE-2026-27459"
                },
                {
                    "category": "description",
                    "text": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27459"
                },
                {
                    "category": "other",
                    "text": "0.0004",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "7.2",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.3",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to (a version of) an uncommon product, VENDOR FIX as product remediation category",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to a product by vendor Red Hat, There is product_remediation data available from source Redhat",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 3\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5839524",
                    "CSAFPID-5843889",
                    "CSAFPID-5843890",
                    "CSAFPID-1439279",
                    "CSAFPID-1439313",
                    "CSAFPID-1441200",
                    "CSAFPID-1441204",
                    "CSAFPID-1455906",
                    "CSAFPID-1508257",
                    "CSAFPID-1508261",
                    "CSAFPID-1508264",
                    "CSAFPID-1771989",
                    "CSAFPID-2518221",
                    "CSAFPID-2698058",
                    "CSAFPID-2698059",
                    "CSAFPID-2976378",
                    "CSAFPID-3023480",
                    "CSAFPID-3093049",
                    "CSAFPID-4534157",
                    "CSAFPID-5008757",
                    "CSAFPID-5008758",
                    "CSAFPID-5009266",
                    "CSAFPID-5119831",
                    "CSAFPID-5172458",
                    "CSAFPID-5172459",
                    "CSAFPID-5172461",
                    "CSAFPID-5355695",
                    "CSAFPID-5811359",
                    "CSAFPID-5846025",
                    "CSAFPID-5846026",
                    "CSAFPID-5846027",
                    "CSAFPID-5846029",
                    "CSAFPID-5846039",
                    "CSAFPID-5846040",
                    "CSAFPID-5846041",
                    "CSAFPID-5874051",
                    "CSAFPID-5874052",
                    "CSAFPID-5906992"
                ],
                "known_not_affected": [
                    "CSAFPID-1439315",
                    "CSAFPID-1439317",
                    "CSAFPID-1439321",
                    "CSAFPID-1439328",
                    "CSAFPID-1441193",
                    "CSAFPID-1441197",
                    "CSAFPID-2855768",
                    "CSAFPID-5276235",
                    "CSAFPID-5846030",
                    "CSAFPID-5846032",
                    "CSAFPID-5846033",
                    "CSAFPID-5846035",
                    "CSAFPID-5846036",
                    "CSAFPID-5846037"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-5pwr-322w-8jr4"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-5pwr-322w-8jr4"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-27459"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/27xxx/CVE-2026-27459.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27459"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27459"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-27459"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-27459"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-27459"
                },
                {
                    "category": "external",
                    "summary": "Source raw - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-27459.json"
                },
                {
                    "category": "external",
                    "summary": "Source - microsoft",
                    "url": "https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Mar"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-5pwr-322w-8jr4"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-27459"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; redhat",
                    "url": "https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-5pwr-322w-8jr4"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-27459"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27459"
                }
            ],
            "remediations": [
                {
                    "category": "mitigation",
                    "details": "To mitigate this flaw, ensure the callback provided to the set_cookie_generate_callback function strictly limits the returned cookie string or byte sequence to under 256 bytes.",
                    "product_ids": [
                        "CSAFPID-1439279",
                        "CSAFPID-1439313",
                        "CSAFPID-1439315",
                        "CSAFPID-1439317",
                        "CSAFPID-1439321",
                        "CSAFPID-1439328",
                        "CSAFPID-1441193",
                        "CSAFPID-1441197",
                        "CSAFPID-1441200",
                        "CSAFPID-1441204",
                        "CSAFPID-1455906",
                        "CSAFPID-1508257",
                        "CSAFPID-1508261",
                        "CSAFPID-1508264",
                        "CSAFPID-1771989",
                        "CSAFPID-2518221",
                        "CSAFPID-2698058",
                        "CSAFPID-2698059",
                        "CSAFPID-2855768",
                        "CSAFPID-2976378",
                        "CSAFPID-3023480",
                        "CSAFPID-3093049",
                        "CSAFPID-4534157",
                        "CSAFPID-5008757",
                        "CSAFPID-5008758",
                        "CSAFPID-5009266",
                        "CSAFPID-5119831",
                        "CSAFPID-5172458",
                        "CSAFPID-5172459",
                        "CSAFPID-5172461",
                        "CSAFPID-5276235",
                        "CSAFPID-5355695",
                        "CSAFPID-5811359",
                        "CSAFPID-5846025",
                        "CSAFPID-5846026",
                        "CSAFPID-5846027",
                        "CSAFPID-5846029",
                        "CSAFPID-5846030",
                        "CSAFPID-5846032",
                        "CSAFPID-5846033",
                        "CSAFPID-5846035",
                        "CSAFPID-5846036",
                        "CSAFPID-5846037",
                        "CSAFPID-5846039",
                        "CSAFPID-5846040",
                        "CSAFPID-5846041"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "CBL-Mariner Releases",
                    "product_ids": [
                        "CSAFPID-5874051"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-1439279",
                        "CSAFPID-1439313",
                        "CSAFPID-1441200",
                        "CSAFPID-1441204",
                        "CSAFPID-1455906",
                        "CSAFPID-1508257",
                        "CSAFPID-1508261",
                        "CSAFPID-1508264",
                        "CSAFPID-1771989",
                        "CSAFPID-2518221",
                        "CSAFPID-2698058",
                        "CSAFPID-2698059",
                        "CSAFPID-2976378",
                        "CSAFPID-3023480",
                        "CSAFPID-3093049",
                        "CSAFPID-4534157",
                        "CSAFPID-5008757",
                        "CSAFPID-5008758",
                        "CSAFPID-5009266",
                        "CSAFPID-5119831",
                        "CSAFPID-5172458",
                        "CSAFPID-5172459",
                        "CSAFPID-5172461",
                        "CSAFPID-5355695",
                        "CSAFPID-5811359",
                        "CSAFPID-5839524",
                        "CSAFPID-5843889",
                        "CSAFPID-5843890",
                        "CSAFPID-5846025",
                        "CSAFPID-5846026",
                        "CSAFPID-5846027",
                        "CSAFPID-5846029",
                        "CSAFPID-5846039",
                        "CSAFPID-5846040",
                        "CSAFPID-5846041",
                        "CSAFPID-5874051",
                        "CSAFPID-5874052",
                        "CSAFPID-5906992"
                    ]
                }
            ],
            "title": "CVE-2026-27459"
        }
    ]
}