CRITICAL 9.3 NVD
CVE-2026-74889
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinis
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-j9mh-57cc-665x
- https://www.vulncheck.com/advisories/openssl-encrypt-before-weak-key-derivation-via-hkdf
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-17 via NVD.
Risk Timeline
CVE Disclosed2026-08-17 · -1 days ago
Remediation Resources
vulnfeed aggregates 11766 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.