9.8
CVE-2026-74889
- EPSS 0.2%
- Veröffentlicht 17.08.2026 11:04:53
- Zuletzt bearbeitet 01.09.2026 15:26:32
- Erkennungen
openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jahlives ≫ Openssl Encrypt SwPlatform python Version < 1.4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.104 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 9.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-j9mh-57cc-665x
https://www.vulncheck.com/advisories/openssl-encrypt-before-weak-key-derivation-via-hkdf