PT-2026-76625 · Pecl · Openssl-Encrypt

CVE-2026-74889

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description Key normalization functions use HKDF (HMAC-based Extract-and-Expand Key Derivation Function) without a salt and with a static info parameter. This reduces entropy extraction and determinism, allowing attackers to exploit predictable key derivation when identical inputs are used, which weakens cryptographic security against multi-target attacks.
Recommendations Update openssl encrypt to version 1.4.0 or later.

Exploit

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74889
GHSA-J9MH-57CC-665X
PYSEC-2026-3765

Affected Products

Openssl-Encrypt