LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-74879

jahlives · openssl encrypt

Published
CVSS7.5
Severityhigh
WeaknessCWE-209
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-74879

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-74879.