Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74880: OpenSSL accepts refresh tokens in URLs, risking exposure
CVE-2026-74880 · published 1 month ago
Summary
OpenSSL's keyserver and telemetry servers accept refresh tokens in URLs, making them visible in server logs, browser history, and other places. This puts sensitive information at risk. To fix, refresh tokens should be sent in the request body instead of as URL parameters.
What to do
- Update tobi openssl-encrypt to version 1.4.0.
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | tobi | openssl-encrypt |
< 1.4.0 Fix: upgrade to 1.4.0
|
| – | jahlives | openssl_encrypt | < 1.4.0 |
| PyPI | tobi | openssl-encrypt |
< 1.4.0 Fix: upgrade to 1.4.0
|
Original advisory text
openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-4rh7-jwg9-m... Mitigation Vendor Advisory
- https://github.com/jahlives/openssl_encrypt/commit/4b2adb05cde8a7ee03cdd271755da...
- https://github.com/advisories/GHSA-4rh7-jwg9-m28m
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74880... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74880 Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-token-leakage-via-qu... Third Party Advisory
- https://github.com/jahlives/openssl_encrypt Product
Severity
9.3
Critical
CVSS 4.0: 6.6 (GHSA)
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-598Use of HTTP Request With Sensitive Query String
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen1 Apr 2026
Sources
CVE-2026-74880 · MITRE
CVE-2026-74880 · NVD
GHSA-4rh7-jwg9-m28m · OSV
GHSA-4rh7-jwg9-m28m · GHSA
CVE-2026-74880 · OSV
Track software like this
Free during beta