Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74889: jahlives/openssl_encrypt before 1.4.0 can create predictable keys

CVE-2026-74889 · published 1 month ago
Summary

The encryption function in jahlives/openssl_encrypt versions earlier than 1.4.0 builds encryption keys in a way that can be guessed when the same data is used repeatedly. This makes the encrypted information easier for attackers to break, especially if they target many similar messages. Update to version 1.4.0 or later to use the corrected key‑generation method.

What to do
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-326Inadequate Encryption Strength
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-74889 · MITRE
Track software like this
Free during beta