{"apiVersion":"1.0","identifier":"CVE-2026-74871","description":"openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and perform offline password cracking at SHA-256 speed instead of the configured KDF cost.","publishedAt":"2026-08-17T11:16:41","lastModifiedAt":"2026-08-17T18:18:15","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74871","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00093,"riskScore":0.63,"affectedProduct":"openssl_encrypt","affectedVersions":"<1.4.6","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74871","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74871","en":"https://www.redsauce.net/en/cves/CVE-2026-74871","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74871","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74871","de":"https://www.redsauce.net/de/cves/CVE-2026-74871","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74871","el":"https://www.redsauce.net/el/cves/CVE-2026-74871"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74871"}}