Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74890: jahlives/openssl_encrypt before 1.4.0 can skip integrity check
CVE-2026-74890 · published 1 month ago
Summary
Versions of the jahlives/openssl_encrypt library older than 1.4.0 may stop creating and checking the security tag that verifies encrypted data when a specific environment setting is present. An attacker who can run code on the system could manipulate this setting to produce ciphertext that cannot be trusted. Upgrade to version 1.4.0 or later, or ensure the environment variable is never set, to keep encryption integrity intact.
What to do
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.0 |
Original advisory text
openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticated ciphertext and bypass integrity protection on encrypted data.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-rvc2-5jxq-g... Mitigation Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-hmac-authentication-... Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74890... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74890 Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 5.5 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-345Insufficient Verification of Data Authenticity
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Track software like this
Free during beta