PT-2026-76614 · Unknown · Openssl-Encrypt

CVE-2026-74878

·

Published

2026-03-31

·

Updated

2026-08-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description The software uses an in-memory rate limiter for Time-based One-Time Password (TOTP) brute-force protection. Because this limiter is not shared across workers and is cleared upon server restart, attackers can bypass these protections by distributing authentication attempts across multiple server instances or by initiating retries immediately after a restart.
Recommendations Update to version 1.4.0 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74878
GHSA-H45M-MGCP-Q388
PYSEC-2026-3757

Affected Products

Openssl-Encrypt