jahlives openssl_encrypt是jahlives个人开发者的一款服务器端数据加密处理工具。 jahlives openssl_encrypt 1.4.0之前版本存在加密问题漏洞,该漏洞源于generate_pseudorandom_sequence函数使用Python的非加密随机模块进行隐写像素选择,可能导致知道密码的攻击者恢复梅森旋转器状态并预测包含隐藏数据的像素位置进行提取,造成信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jahlives | openssl_encrypt | < 1.4.0 |
affected |
1.4.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jahlives | openssl_encrypt | 0 ~ 1.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-74878 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass |
| CVE-2026-74901 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback |
| CVE-2026-74900 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode |
| CVE-2026-74889 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF |
| CVE-2026-74880 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Token Leakage via Query Parameters |
| CVE-2026-74894 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token |
| CVE-2026-74876 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption |
| CVE-2026-74896 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal |
| CVE-2026-74875 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Schema Validation Bypass |
| CVE-2026-74886 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Plugin Import Guard Bypass |
| CVE-2026-74899 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy |
| CVE-2026-74872 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool |
| CVE-2026-74895 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation |
| CVE-2026-74891 | 9.8 CRITICAL | openssl_encrypt before 1.4.0 Hardcoded Database Credentials |
| CVE-2026-74877 | 8.8 HIGH | openssl_encrypt before 1.4.0 Missing Ownership Verification via revoke_key |
| CVE-2026-74893 | 8.8 HIGH | openssl_encrypt before 1.4.0 JWT Token Forgery via Hardcoded Secrets |
| CVE-2026-74883 | 8.8 HIGH | openssl_encrypt before 1.4.0 Sandbox Bypass via pathlib and io |
| CVE-2026-74884 | 7.5 HIGH | openssl_encrypt before 1.4.0 Path Traversal via plugin_id |
| CVE-2026-74888 | 7.5 HIGH | openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation |
| CVE-2026-74892 | 7.5 HIGH | openssl_encrypt before 1.4.0 Hardcoded Secret Key |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet