Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74889: jahlives/openssl_encrypt before 1.4.0 can create predictable keys
CVE-2026-74889 · published 1 month ago
Summary
The encryption function in jahlives/openssl_encrypt versions earlier than 1.4.0 builds encryption keys in a way that can be guessed when the same data is used repeatedly. This makes the encrypted information easier for attackers to break, especially if they target many similar messages. Update to version 1.4.0 or later to use the corrected key‑generation method.
What to do
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.0 |
Original advisory text
openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-j9mh-57cc-6... Mitigation Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-weak-key-derivation-... Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74889... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74889 Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-326Inadequate Encryption Strength
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Track software like this
Free during beta