CVE-2026-74889
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-326
- Published
- 2026-08-17
- Last modified
- 2026-08-17
Affected products
- jahlives openssl_encrypt
- jahlives openssl_encrypt
Weakness type
Related vulnerabilities
- CVE-2026-86670 — aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
- CVE-2023-54356 — Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites
- CVE-2026-81718 — openssl_encrypt before 1.4.9 Weak Cryptographic Parameters
- CVE-2026-79084 — Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to...
- CVE-2026-65777 — Active Directory Security Feature Bypass Vulnerability
- CVE-2026-9201 — Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
- CVE-2026-59651 — BKS keystore accepts legacy version with 16-bit integrity MAC key
- CVE-2026-4648 — Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands