PT-2026-76634 · Pypi · Openssl-Encrypt
CVE-2026-74900
·
Published
2026-08-17
·
Updated
2026-08-18
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.0
Description
A critical issue exists in
pqc.py where Key Encapsulation Mechanism (KEM) decapsulation failures silently revert to a simulation mode. In this mode, a deterministic shared secret is generated using only 16 bytes of the private key and publicly available encapsulated key data. Because the fallback occurs without raising an error, an attacker who obtains 16 bytes of the private key can compute the shared secret and decrypt all ciphertext.Recommendations
Update openssl encrypt to version 1.4.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt