CVE-2026-27459: Pyopenssl Dtls Cookie Callback Buffer Overflow

The DTLS cookie-generate callback wrapper copies the callback-returned cookie bytes into the fixed-size OpenSSL `out` buffer via `out[0:len(cookie)] = cookie` without first bounding the cookie length against DTLS1_COOKIE_LENGTH (255). A callback returning more than 255 bytes overflows the OpenSSL-provided buffer (CVE-2026-27459, CWE-120). Add `if len(cookie)

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-27459-pyopenssl-dtls-cookie-callback-buffer-overflow --engine opengrep

Description

The DTLS cookie-generate callback wrapper copies the callback-returned cookie bytes into the fixed-size OpenSSL `out` buffer via `out[0:len(cookie)] = cookie` without first bounding the cookie length against DTLS1_COOKIE_LENGTH (255). A callback returning more than 255 bytes overflows the OpenSSL-provided buffer (CVE-2026-27459, CWE-120). Add `if len(cookie)