LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-74872

jahlives · openssl encrypt

Published
CVSS9.8
Severitycritical
WeaknessCWE-426
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-74872

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-74872.