HIGHVulnerability

CVE-2026-74879

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.

Properties

severity
HIGH
score
7.5
epss_score
0.00259
cve_id
CVE-2026-74879
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-17T11:16:42.460
last_modified
2026-09-01T15:28:17.557
epss_percentile
0.17347

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Generation of Error Message Containing Sensitive Information

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-74879 — Ninja Signal Threat Intelligence | Ninja Signal