Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74901: openssl_encrypt before 1.4.0 lets altered data pass unchecked

CVE-2026-74901 · published 1 month ago
Summary

The openssl_encrypt library versions earlier than 1.4.0 may skip important checks when decryption fails, falling back to a weaker method that does not verify data integrity. This means an attacker could change encrypted messages without being detected and potentially manipulate the content. Update to version 1.4.0 or later to ensure proper verification of encrypted data.

What to do
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-74901 · MITRE
Track software like this
Free during beta