CVE-2026-74896
- EPSS 0.34%
- Veröffentlicht 17.08.2026 11:04:57
- Zuletzt bearbeitet 01.09.2026 15:24:52
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globa...
CVE-2026-74894
- EPSS 0.39%
- Veröffentlicht 17.08.2026 11:04:56
- Zuletzt bearbeitet 01.09.2026 15:25:06
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revok...
CVE-2026-74893
- EPSS 0.26%
- Veröffentlicht 17.08.2026 11:04:55
- Zuletzt bearbeitet 01.09.2026 15:25:14
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver ...
CVE-2026-74892
- EPSS 0.31%
- Veröffentlicht 17.08.2026 11:04:55
- Zuletzt bearbeitet 31.08.2026 15:48:21
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise te...
CVE-2026-74891
- EPSS 0.28%
- Veröffentlicht 17.08.2026 11:04:54
- Zuletzt bearbeitet 01.09.2026 15:25:29
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.
CVE-2026-74890
- EPSS 0.17%
- Veröffentlicht 17.08.2026 11:04:53
- Zuletzt bearbeitet 01.09.2026 15:26:20
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set ...
CVE-2026-74889
- EPSS 0.2%
- Veröffentlicht 17.08.2026 11:04:53
- Zuletzt bearbeitet 01.09.2026 15:26:32
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken crypto...
CVE-2026-74888
- EPSS 0.17%
- Veröffentlicht 17.08.2026 11:04:52
- Zuletzt bearbeitet 01.09.2026 15:26:41
openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key...
CVE-2026-74887
- EPSS 0.21%
- Veröffentlicht 17.08.2026 11:04:51
- Zuletzt bearbeitet 31.08.2026 15:49:13
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently aff...
CVE-2026-74886
- EPSS 0.4%
- Veröffentlicht 17.08.2026 11:04:51
- Zuletzt bearbeitet 01.09.2026 15:26:49
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscat...