openssl-encrypt
PyPI8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openssl-encryptpage 1 of 1
- CVE-2026-74872CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.4.02026-08-17
vulnerable: 0.2.2 ... 1.4.0b8 (44 versions)
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .s…
- CVE-2026-74873MEDIUMCVSS 5.5EG 5.5✓ Fixed in 1.4.02026-08-17
vulnerable: 0.2.2 ... 1.4.0b8 (44 versions)
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaint…
- CVE-2026-74875CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.4.02026-08-17
vulnerable: 0.2.2 ... 1.4.0b8 (44 versions)
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata for…
- CVE-2026-74876CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.4.02026-08-17
vulnerable: 0.2.2 ... 1.4.0b8 (44 versions)
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signat…
- CVE-2026-74877HIGHCVSS 8.8EG 8.8✓ Fixed in 1.4.02026-08-17
vulnerable: 0.2.2 ... 1.4.0b8 (44 versions)
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a va…
- CVE-2026-74878CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.4.02026-08-17
vulnerable: 0.2.2 ... 1.4.0b8 (44 versions)
openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server in…
- CVE-2026-74880CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.4.02026-08-17
vulnerable: 0.2.2 ... 1.4.0b8 (44 versions)
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unau…
- CVE-2026-74881MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.4.02026-08-17
vulnerable: 0.2.2 ... 1.4.0b8 (44 versions)
openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of an…
Check whether openssl-encrypt is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openssl-encrypt CVEs against the assets you own.
Start Free Scan →