CRITICAL 9.3 NVD
CVE-2026-74875
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accep
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-425g-fjhq-5h92
- https://www.vulncheck.com/advisories/openssl-encrypt-before-schema-validation-bypass
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-17 via NVD.
Risk Timeline
CVE Disclosed2026-08-17 · -1 days ago
Remediation Resources
vulnfeed aggregates 11766 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.