Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74885: jahlives/openssl_encrypt may lose audit logs and unblock modules
CVE-2026-74885 · published 1 month ago
Summary
Versions of jahlives/openssl_encrypt earlier than 1.4.0 write the wrong numbers in their logs, making it look like no hidden components were restored. In systems that run many tasks at once, a timing problem can let previously blocked components be loaded again. Upgrade to version 1.4.0 or later (or apply the supplied fix) and restart the application.
What to do
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.0 |
Original advisory text
openssl_encrypt before 1.4.0 Logging Bug and Race Condition
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-43r4-3hf9-m... Mitigation Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-logging-bug-and-race... Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74885... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74885 Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 3.6 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-117Improper Output Neutralization for Logs
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Track software like this
Free during beta