PT-2026-76634 · Pypi · Openssl-Encrypt

CVE-2026-74900

·

Published

2026-08-17

·

Updated

2026-08-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.0
Description A critical issue exists in pqc.py where Key Encapsulation Mechanism (KEM) decapsulation failures silently revert to a simulation mode. In this mode, a deterministic shared secret is generated using only 16 bytes of the private key and publicly available encapsulated key data. Because the fallback occurs without raising an error, an attacker who obtains 16 bytes of the private key can compute the shared secret and decrypt all ciphertext.
Recommendations Update openssl encrypt to version 1.4.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74900
GHSA-P3GQ-PCG9-QVFV
PYSEC-2026-3772

Affected Products

Openssl-Encrypt