Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74878: OpenSSL TOTP Rate Limiter Not Shared Across Workers, Lost on Restart
CVE-2026-74878 · published 1 month ago
Summary
The OpenSSL TOTP rate limiter doesn't share its state across multiple workers or save its state when the server restarts, making it vulnerable to brute-force attacks. This can allow an attacker to try many combinations quickly without being detected. To fix this, you should use a shared storage solution like Redis or a database to store the rate limit state, or implement a shared-memory approach for multi-worker deployments.
What to do
- Update tobi openssl-encrypt to version 1.4.0.
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | tobi | openssl-encrypt |
< 1.4.0 Fix: upgrade to 1.4.0
|
| – | jahlives | openssl_encrypt | < 1.4.0 |
Original advisory text
openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate limiting protections.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-h45m-mgcp-q... Mitigation Vendor Advisory
- https://github.com/jahlives/openssl_encrypt/commit/2749bc0949b34a5921a35fb4a3f18...
- https://github.com/advisories/GHSA-h45m-mgcp-q388
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74878... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74878 Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-totp-rate-limiter-by... Third Party Advisory
Severity
9.3
Critical
CVSS 4.0: 9.1 (GHSA)
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-770Allocation of Resources Without Limits
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen1 Apr 2026
Track software like this
Free during beta