What is CVE-2026-74875?
CVE-2026-74875 in openssl_encrypt before version 1.4.0 allows silent bypass of JSON schema validation when the jsonschema library is missing, enabling attackers to supply malicious metadata. This affects systems relying on openssl_encrypt, and users should upgrade to version 1.4.0 or later while ensuring the jsonschema dependency is installed.
Azərbaycanca: CVE-2026-74875 openssl_encrypt kitabxanasının 1.4.0-dan əvvəlki versiyalarında jsonschema modulu quraşdırılmayanda JSON schema yoxlanışının səssizcə atlanmasına səbəb olur ki, bu da təhlükəsizlik yoxlamalarından yan keçməyə və zərərli metadata qəbuluna yol açır. Bu zəiflik openssl_encrypt istifadə edən sistemlərə təsir edir. İstifadəçilər dərhal 1.4.0 və ya daha yuxarı versiyaya yeniləməli, həmçinin jsonschema asılılığının mütləq quraşdırıldığından əmin olmalıdırlar.
FAQ2
Which versions of the openssl_encrypt library are affected by CVE-2026-74875?
CVE-2026-74875 affects versions of openssl_encrypt before 1.4.0.
What measures should be taken to mitigate CVE-2026-74875?
Users should upgrade to openssl_encrypt version 1.4.0 or later and ensure the jsonschema dependency is installed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.