PT-2026-76610 · Pypi · Openssl-Encrypt

CVE-2026-74874

·

Published

2026-03-31

·

Updated

2026-08-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description The generate pseudorandom sequence() function uses Python's non-cryptographic random module for steganographic pixel selection. An attacker who knows the password can recover the Mersenne Twister state—a deterministic algorithm used to generate pseudo-random numbers—from approximately 624 outputs. This allows the attacker to predict the pixel locations containing hidden data and extract it.
Recommendations Update openssl encrypt to version 1.4.0 or later.

Exploit

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74874
GHSA-VFGX-5Q85-58Q3
PYSEC-2026-3754

Affected Products

Openssl-Encrypt