← Späť na vyhľadávanie CVE

CVE-2026-74889

openssl_encrypt

Popis

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

CVSS 9.8EPSS 0.201%Riziko 1
Zobraziť zdroj
Zverejnené
2026-08-17 11:16:43
Dotknuté verzie
<1.4.0
Typ
Knižnica
Posledná úprava
2026-08-17 16:17:50
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H