LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-74889

jahlives · openssl encrypt

Published
CVSS9.8
Severitycritical
WeaknessCWE-326
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-74889

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-74889.