PT-2026-76606 · Pypi · Openssl-Encrypt

CVE-2026-74870

·

Published

2026-08-17

·

Updated

2026-09-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions openssl encrypt (pip) versions prior to 1.4.8
Description An information exposure issue exists where the diagnostic commands 'hsm fido2-test' and 'hsm onlykey-test' unconditionally print the full derived hardware pepper as hex to stdout/stderr via the handle hsm command function in crypt cli.py. This sensitive data may persist in terminal scrollback, session recordings, or CI logs. Additionally, a plugin issue caused raw prf data to be logged outside the secret-redaction path. The impact is limited as the pepper is salt-bound and derived from a random per-invocation test salt, preventing its use in decrypting actual files.
Recommendations Update to version 1.4.8 or later.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74870
GHSA-P9G8-WVH4-2JMX
PYSEC-2026-3956

Affected Products

Openssl-Encrypt