PT-2026-76610 · Pypi · Openssl-Encrypt
CVE-2026-74874
·
Published
2026-03-31
·
Updated
2026-08-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.0
Description
The
generate pseudorandom sequence() function uses Python's non-cryptographic random module for steganographic pixel selection. An attacker who knows the password can recover the Mersenne Twister state—a deterministic algorithm used to generate pseudo-random numbers—from approximately 624 outputs. This allows the attacker to predict the pixel locations containing hidden data and extract it.Recommendations
Update openssl encrypt to version 1.4.0 or later.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl-Encrypt