CVE-2026-74875
- EPSS 0.19%
- Veröffentlicht 17.08.2026 11:04:43
- Zuletzt bearbeitet 08.10.2026 16:17:39
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format version...
CVE-2026-74874
- EPSS 0.26%
- Veröffentlicht 17.08.2026 11:04:42
- Zuletzt bearbeitet 08.10.2026 16:17:39
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approxim...
CVE-2026-74873
- EPSS 0.23%
- Veröffentlicht 17.08.2026 11:04:42
- Zuletzt bearbeitet 08.10.2026 16:17:38
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwor...
CVE-2026-74872
- EPSS 0.46%
- Veröffentlicht 17.08.2026 11:04:41
- Zuletzt bearbeitet 08.10.2026 16:17:38
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files mat...
CVE-2026-74870
- EPSS 0.19%
- Veröffentlicht 17.08.2026 11:04:40
- Zuletzt bearbeitet 03.09.2026 16:07:10
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, ...
CVE-2026-74871
- EPSS 0.09%
- Veröffentlicht 17.08.2026 11:04:40
- Zuletzt bearbeitet 10.09.2026 16:56:31
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-h...