CVE-2026-74889: Jahlives OpenSSL Encrypt

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

Affected products

  • Jahlives OpenSSL Encrypt: before 1.4.0 (fixed in 1.4.0)

Published 2026-08-17. Last modified 2026-09-01.