← Volver al buscador de CVEs

CVE-2026-74889

openssl_encrypt

Descripción

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

CVSS 9.8EPSS 0.201%Riesgo 1
Ver fuente
Publicación
2026-08-17 11:16:43
Versiones afectadas
<1.4.0
Tipo
Librería
Última modificación
2026-08-17 16:17:50
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H