CVE-2026-74901Disclosure(jahlives / openssl_encrypt)

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch jahlives openssl_encrypt systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl_encrypt

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
openssl_encrypt

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-17: 3Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 208-17
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en Libreria de Python ❗ CVE-2026-74901 ❗ CVE-2026-74900 ❗ CVE-2026-74896 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-libreria-de-python/ https://t.co/PLKCikgWT5

    Post summary

    The post enumerates three Python‑library CVEs and links to a CERT webpage for further details, but offers no specific exploit, mitigation, or technical information.

    01010186
    6.7K followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    A critical `openssl_encrypt` flaw (CVE-2026-74901) was just revealed (Aug 17, 2026). It permits unauthenticated attackers to modify encrypted data in transit, severely compromising data integrity and privacy. Patch immediately. #Cybersecurity #Vulnerability #News

    Post summary

    A critical flaw (CVE‑2026‑74901) in OpenSSL encryption permitting unauthenticated modification of encrypted data is disclosed, and an urgent patch is advised.

    0000031
    17 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-74901 openssl_encrypt Authentication Bypass via AES-GCM Fallback https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-74901

    Post summary

    This entry announces CVE-2026-74901, an authentication bypass in openssl_encrypt due to AES‑GCM fallback, but provides no PoC, exploit, patch, or active exploitation evidence.

    0000091
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjahlivesopenssl_encrypt-python-

Explore more