Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74880: OpenSSL accepts refresh tokens in URLs, risking exposure

CVE-2026-74880 · published 1 month ago
Summary

OpenSSL's keyserver and telemetry servers accept refresh tokens in URLs, making them visible in server logs, browser history, and other places. This puts sensitive information at risk. To fix, refresh tokens should be sent in the request body instead of as URL parameters.

What to do
  • Update tobi openssl-encrypt to version 1.4.0.
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
Ecosystem VendorProductAffected versions
pip tobi openssl-encrypt < 1.4.0
Fix: upgrade to 1.4.0
– jahlives openssl_encrypt < 1.4.0
PyPI tobi openssl-encrypt < 1.4.0
Fix: upgrade to 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
Severity
9.3 Critical
CVSS 4.0: 6.6 (GHSA)
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-598Use of HTTP Request With Sensitive Query String
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen1 Apr 2026
Track software like this
Free during beta