What is CVE-2026-74871?
CVE-2026-74871 is a key derivation flaw in openssl_encrypt versions before 1.4.6 within sequential XOR composition mode, where the last stage cancels out during key generation. This allows attackers to bypass memory-hard key derivation when a single KDF without prior hashing is used, enabling offline password cracking. Users should upgrade to version 1.4.6 or later.
Azərbaycanca: CVE-2026-74871 openssl_encrypt kitabxanasının 1.4.6-dan əvvəlki versiyalarında sequential XOR composition rejimində açar törətmə qüsurudur. Bu qüsur son mərhələnin ləğv olması nəticəsində memory-hard key derivation müdafiəsini keçərək offline parol sındırma hücumlarına imkan yaradır. İstifadəçilərə 1.4.6 və ya daha yuxarı versiyalara yeniləmə tövsiyə olunur.
FAQ2
Which library is affected by CVE-2026-74871?
CVE-2026-74871 affects openssl_encrypt library versions before 1.4.6.
What type of attack does this flaw enable?
This flaw allows attackers to bypass memory-hard key derivation, enabling offline password cracking.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.