Vulnerability Description
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jahlives | Openssl Encrypt | < 1.4.0 |
Related Weaknesses (CWE)
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-j48q-4c78-rMitigationVendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-arbitrary-code-execuThird Party Advisory
FAQ
What is CVE-2026-74872?
CVE-2026-74872 is a vulnerability with a CVSS score of 9.8 (CRITICAL). openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verific...
How severe is CVE-2026-74872?
CVE-2026-74872 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-74872?
Check the references section above for vendor advisories and patch information. Affected products include: Jahlives Openssl Encrypt.