Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74876: OpenSSL: Unverified Encryption Keys Can Leak Secrets

CVE-2026-74876 · published 1 month ago
Summary

A recent OpenSSL update fixes a security issue where encryption keys are not properly verified before use. This could allow an attacker to steal sensitive information. To fix this, the update requires developers to verify the keys before using them for encryption.

What to do
  • Update tobi openssl-encrypt to version 1.4.0.
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
Ecosystem VendorProductAffected versions
pip tobi openssl-encrypt < 1.4.0
Fix: upgrade to 1.4.0
– jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.
Severity
9.3 Critical
CVSS 4.0: 6.6 (GHSA)
CVSS 4.0: 9.3 (NVD)
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen1 Apr 2026
Sources
CVE-2026-74876 · MITRE
Track software like this
Free during beta