Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74900: openssl_encrypt before 1.4.0 may expose encrypted data
CVE-2026-74900 · published 1 month ago
Summary
Versions of openssl_encrypt older than 1.4.0 can silently switch to a weakened mode when a key operation fails, using only a small part of the private key to create a predictable secret. If an attacker learns just 16 bytes of that private key, they can recover the secret and read any encrypted messages. Update to version 1.4.0 or later to stop the fallback and protect your data.
What to do
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.0 |
Original advisory text
openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the private key can compute the shared secret and decrypt all ciphertext, as the fallback triggers on any KEM failure without raising an error.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-p3gq-pcg9-q... Mitigation Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-weak-shared-secret-v... Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74900... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74900 Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-391Unchecked Error Condition
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Track software like this
Free during beta