Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-74877: OpenSSL client can revoke any key without permission
CVE-2026-74877 · published 1 month ago
Summary
Any client can revoke another client's key, potentially disrupting communication. This can happen because the OpenSSL software doesn't check who is trying to revoke a key before allowing it. To fix this, the software needs to be updated to verify the owner of the key before allowing revocation. This issue has already been fixed in a newer version of OpenSSL.
What to do
- Update tobi openssl-encrypt to version 1.4.0.
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | tobi | openssl-encrypt |
< 1.4.0 Fix: upgrade to 1.4.0
|
| – | jahlives | openssl_encrypt | < 1.4.0 |
| PyPI | tobi | openssl-encrypt |
< 1.4.0 Fix: upgrade to 1.4.0
|
Original advisory text
openssl_encrypt before 1.4.0 Missing Ownership Verification via revoke_key
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-hvc7-763r-4... Mitigation Vendor Advisory
- https://github.com/jahlives/openssl_encrypt/commit/05e45f393886b5bf7e924d2dd4209...
- https://github.com/advisories/GHSA-hvc7-763r-4f3h
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74877... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74877 Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-missing-ownership-ve... Third Party Advisory
- https://github.com/jahlives/openssl_encrypt Product
Severity
8.7
High
CVSS 4.0: 6.6 (GHSA)
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen1 Apr 2026
Sources
CVE-2026-74877 · MITRE
CVE-2026-74877 · NVD
GHSA-hvc7-763r-4f3h · OSV
GHSA-hvc7-763r-4f3h · GHSA
CVE-2026-74877 · OSV
Track software like this
Free during beta