CVE-2026-74873: Jahlives OpenSSL Encrypt
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.
Affected products
- Jahlives OpenSSL Encrypt: before 1.4.0 (fixed in 1.4.0)
Published 2026-08-17. Last modified 2026-10-08.