Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openssl_encrypt — Vulnerabilities & Security Advisories 30

All 30 CVE vulnerabilities found in openssl_encrypt, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the openssl_encrypt module, focusing on weakness classifications and associated security risks. It compiles a comprehensive list of known vulnerabilities affecting this specific cryptographic function, covering security issues reported from 2015 to the present. This collection includes entries derived from vendor advisories, third-party security research, and public vulnerability databases, ensuring a broad view of the threat landscape for developers and system administrators. Visitors to this page can track security advisories issued by relevant vendors to stay informed about patches and mitigation strategies. By exploring the detailed entries, users can gain a deeper understanding of the underlying weakness classes that impact the openssl_encrypt functionality, such as improper input validation or cryptographic failures. Furthermore, the page serves as a historical record, allowing users to look up the vulnerability history of the product to assess long-term security trends and potential exposure. This structured approach facilitates better risk management by providing context for each identified issue, helping stakeholders prioritize remediation efforts based on severity and relevance. The information presented is intended to support secure development practices and operational security by highlighting critical flaws that may compromise data integrity or confidentiality when the openssl_encrypt API is utilized in various software environments.

Vendor: jahlives

CVE IDTitleCVSSSeverityPublished
CVE-2026-74901 openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback CWE-347 9.8 Critical2026-08-17
CVE-2026-74899 openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy CWE-95 9.8 Critical2026-08-17
CVE-2026-74900 openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode CWE-391 9.8 Critical2026-08-17
CVE-2026-74896 openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal CWE-693 9.8 Critical2026-08-17
CVE-2026-74895 openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation CWE-693 9.8 Critical2026-08-17
CVE-2026-74894 openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token CWE-287 9.8 Critical2026-08-17
CVE-2026-74893 openssl_encrypt before 1.4.0 JWT Token Forgery via Hardcoded Secrets CWE-798 8.8 High2026-08-17
CVE-2026-74891 openssl_encrypt before 1.4.0 Hardcoded Database Credentials CWE-798 9.8 Critical2026-08-17
CVE-2026-74892 openssl_encrypt before 1.4.0 Hardcoded Secret Key CWE-798 7.5 High2026-08-17
CVE-2026-74890 openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable CWE-345 5.5 Medium2026-08-17
CVE-2026-74889 openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF CWE-326 9.8 Critical2026-08-17
CVE-2026-74888 openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation CWE-327 7.5 High2026-08-17
CVE-2026-74887 openssl_encrypt before 1.4.0 Insecure Random Import in PQC Module CWE-338--2026-08-17
CVE-2026-74886 openssl_encrypt before 1.4.0 Plugin Import Guard Bypass CWE-184 9.8 Critical2026-08-17
CVE-2026-74884 openssl_encrypt before 1.4.0 Path Traversal via plugin_id CWE-73 7.5 High2026-08-17
CVE-2026-74885 openssl_encrypt before 1.4.0 Logging Bug and Race Condition CWE-117 3.6 Low2026-08-17
CVE-2026-74883 openssl_encrypt before 1.4.0 Sandbox Bypass via pathlib and io CWE-693 8.8 High2026-08-17
CVE-2026-74881 openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins CWE-942 6.5 Medium2026-08-17
CVE-2026-74882 openssl_encrypt before 1.4.0 Insecure Default Configuration CWE-345 7.5 High2026-08-17
CVE-2026-74880 openssl_encrypt before 1.4.0 Token Leakage via Query Parameters CWE-598 9.8 Critical2026-08-17
CVE-2026-74878 openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass CWE-770 9.8 Critical2026-08-17
CVE-2026-74879 openssl_encrypt before 1.4.0 Information Disclosure via /ready endpoint CWE-209 7.5 High2026-08-17
CVE-2026-74877 openssl_encrypt before 1.4.0 Missing Ownership Verification via revoke_key CWE-639 8.8 High2026-08-17
CVE-2026-74876 openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption CWE-347 9.8 Critical2026-08-17
CVE-2026-74875 openssl_encrypt before 1.4.0 Schema Validation Bypass CWE-345 9.8 Critical2026-08-17
CVE-2026-74874 openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection CWE-338 7.5 High2026-08-17
CVE-2026-74873 openssl_encrypt before 1.4.0 Password Exposure via CLI Argument CWE-214 5.5 Medium2026-08-17
CVE-2026-74872 openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool CWE-426 9.8 Critical2026-08-17
CVE-2026-74871 openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR CWE-916 6.2 Medium2026-08-17
CVE-2026-74870 openssl_encrypt before 1.4.8 Hardware Pepper Information Disclosure CWE-532 3.3 Low2026-08-17

All 30 known CVE vulnerabilities affecting openssl_encrypt with full Chinese analysis, references, and POCs where available.