Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74875: OpenSSL Encrypt Bypasses Validation Without jsonschema Library
CVE-2026-74875 · published 1 month ago
Summary
A security issue in OpenSSL Encrypt allows an attacker to bypass schema validation if the jsonschema library is not installed or if metadata has an unknown format version. This means malicious or malformed metadata may be accepted without check. To fix, make jsonschema a required dependency, or refuse to process metadata when validation can't be done.
What to do
- Update tobi openssl-encrypt to version 1.4.0.
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | tobi | openssl-encrypt |
< 1.4.0 Fix: upgrade to 1.4.0
|
| – | jahlives | openssl_encrypt | < 1.4.0 |
Original advisory text
openssl_encrypt before 1.4.0 Schema Validation Bypass
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-425g-fjhq-5... Mitigation Vendor Advisory
- https://github.com/jahlives/openssl_encrypt/commit/6e7f938dcb7928faf5fd12bb5559f...
- https://github.com/advisories/GHSA-425g-fjhq-5h92
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74875... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74875 Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-schema-validation-by... Third Party Advisory
Severity
9.3
Critical
CVSS 4.0: 6.6 (GHSA)
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
CWE-345Insufficient Verification of Data Authenticity
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen1 Apr 2026
Track software like this
Free during beta