CRITICALVulnerability
CVE-2026-74889
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
Properties
- severity
- CRITICAL
- score
- 9.8
- epss_score
- 0.00201
- cve_id
- CVE-2026-74889
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-08-17T11:16:43.803
- last_modified
- 2026-09-01T15:26:32.637
- epss_percentile
- 0.1003
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
AFFECTS_PRODUCT (1)
→[Product]
HAS_WEAKNESS (1)
→[Weakness]Inadequate Encryption Strength
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph