CVE-2026-74874CWE-338

CVE-2026-74874

High · published August 17, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
16.9
In the wild
Unconfirmed
What it is

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00255 · 16.9th percentile
Weakness
CWE-338 · Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
Published
2026-08-17T15:16Z
Affected products (1)
ProductVersionsFixed in
jahlives/openssl_encrypt< 1.4.01.4.0
References (2)
EPSS history
Timeline
  • 17 AUG 11:04Z
    openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection
    cvelistv5