Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74900: openssl_encrypt before 1.4.0 may expose encrypted data

CVE-2026-74900 · published 1 month ago
Summary

Versions of openssl_encrypt older than 1.4.0 can silently switch to a weakened mode when a key operation fails, using only a small part of the private key to create a predictable secret. If an attacker learns just 16 bytes of that private key, they can recover the secret and read any encrypted messages. Update to version 1.4.0 or later to stop the fallback and protect your data.

What to do
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode
openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the private key can compute the shared secret and decrypt all ciphertext, as the fallback triggers on any KEM failure without raising an error.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-391Unchecked Error Condition
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-74900 · MITRE
Track software like this
Free during beta