What is CVE-2026-74872?
The openssl_encrypt library before version 1.4.0 contains an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages. Updating to version 1.4.0 is recommended.
Azərbaycanca: openssl_encrypt kitabxanasının 1.4.0-dan əvvəlki versiyalarında Whirlpool hash funksiyasında .so modullarını yükləyərkən geniş glob nümunələrindən istifadə edən ixtiyari kod icrası zəifliyi aşkarlanıb. Təcavüzkar `site-packages` qovluğuna `whirlpool*py313*.so` şablonuna uyğun zərərli fayl yerləşdirə bilər. Kitabxananı 1.4.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of the openssl_encrypt library are affected by CVE-2026-74872?
This vulnerability affects openssl_encrypt library versions before 1.4.0.
What mitigation is recommended for CVE-2026-74872?
Updating the library to version 1.4.0 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.