Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74890: jahlives/openssl_encrypt before 1.4.0 can skip integrity check

CVE-2026-74890 · published 1 month ago
Summary

Versions of the jahlives/openssl_encrypt library older than 1.4.0 may stop creating and checking the security tag that verifies encrypted data when a specific environment setting is present. An attacker who can run code on the system could manipulate this setting to produce ciphertext that cannot be trusted. Upgrade to version 1.4.0 or later, or ensure the environment variable is never set, to keep encryption integrity intact.

What to do
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticated ciphertext and bypass integrity protection on encrypted data.
Severity
9.3 Critical
CVSS 3.1: 5.5 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-345Insufficient Verification of Data Authenticity
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-74890 · MITRE
Track software like this
Free during beta