Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74875: OpenSSL Encrypt Bypasses Validation Without jsonschema Library

CVE-2026-74875 · published 1 month ago
Summary

A security issue in OpenSSL Encrypt allows an attacker to bypass schema validation if the jsonschema library is not installed or if metadata has an unknown format version. This means malicious or malformed metadata may be accepted without check. To fix, make jsonschema a required dependency, or refuse to process metadata when validation can't be done.

What to do
  • Update tobi openssl-encrypt to version 1.4.0.
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
Ecosystem VendorProductAffected versions
pip tobi openssl-encrypt < 1.4.0
Fix: upgrade to 1.4.0
– jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Schema Validation Bypass
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
Severity
9.3 Critical
CVSS 4.0: 6.6 (GHSA)
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
CWE-345Insufficient Verification of Data Authenticity
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen1 Apr 2026
Sources
CVE-2026-74875 · MITRE
Track software like this
Free during beta