Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-74901: openssl_encrypt before 1.4.0 lets altered data pass unchecked
CVE-2026-74901 · published 1 month ago
Summary
The openssl_encrypt library versions earlier than 1.4.0 may skip important checks when decryption fails, falling back to a weaker method that does not verify data integrity. This means an attacker could change encrypted messages without being detected and potentially manipulate the content. Update to version 1.4.0 or later to ensure proper verification of encrypted data.
What to do
- Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.0 |
Original advisory text
openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-w4j7-wfgw-r... Mitigation Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-authentication-bypas... Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74901... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-74901 Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-347Improper Verification of Cryptographic Signature
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Track software like this
Free during beta