CRITICAL 9.3 NVD
CVE-2026-74895
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malic
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-623h-chj7-hfx8
- https://www.vulncheck.com/advisories/openssl-encrypt-before-plugin-sandbox-bypass-via-proc
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-17 via NVD.
Risk Timeline
CVE Disclosed2026-08-17 · -1 days ago
Remediation Resources
vulnfeed aggregates 11766 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.