Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74872: OpenSSL Encryption Before 1.4.0 Allows Malicious Code Execution

CVE-2026-74872 · published 1 month ago
Summary

A vulnerability in OpenSSL's encryption function allows attackers to execute malicious code. This affects older versions of the OpenSSL library, which is used in many applications for secure data encryption. To protect against this, update OpenSSL to version 1.4.0 or later.

What to do
  • Update tobi openssl-encrypt to version 1.4.0.
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
Ecosystem VendorProductAffected versions
pip tobi openssl-encrypt < 1.4.0
Fix: upgrade to 1.4.0
– jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.
Severity
9.3 Critical
CVSS 4.0: 6.6 (GHSA)
CVSS 4.0: 9.3 (NVD)
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-427Uncontrolled Search Path Element
CWE-426Untrusted Search Path
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen1 Apr 2026
Sources
CVE-2026-74872 · MITRE
Track software like this
Free during beta