PT-2026-76608 · Pypi · Openssl-Encrypt
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.0
Description
The Whirlpool hash implementation contains a flaw that allows arbitrary code execution. The issue arises because the software uses broad glob patterns to load
.so modules without verifying their integrity. An attacker can achieve native code execution by placing a malicious .so file that matches the whirlpool*py313*.so pattern within the site-packages directories, which is then executed when the module is loaded.Recommendations
Update openssl encrypt to version 1.4.0 or later.
Exploit
Fix
Untrusted Search Path
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl-Encrypt