PT-2026-76608 · Pypi · Openssl-Encrypt

·

CVE-2026-74872

·

Published

2026-03-31

·

Updated

2026-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description The Whirlpool hash implementation contains a flaw that allows arbitrary code execution. The issue arises because the software uses broad glob patterns to load .so modules without verifying their integrity. An attacker can achieve native code execution by placing a malicious .so file that matches the whirlpool*py313*.so pattern within the site-packages directories, which is then executed when the module is loaded.
Recommendations Update openssl encrypt to version 1.4.0 or later.

Exploit

Fix

Untrusted Search Path

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74872
GHSA-J48Q-4C78-RHF9
PYSEC-2026-3742

Affected Products

Openssl-Encrypt