What is CVE-2026-74885?
CVE-2026-74885 affects 'openssl_encrypt' versions prior to 1.4.0, containing a logging bug in `restore_hidden_modules()` that corrupts audit trails by always showing zero restored modules, along with a race condition between module hiding and import hook installation. Users should upgrade to version 1.4.0 to mitigate the issue.
Azərbaycanca: CVE-2026-74885 'openssl_encrypt' modulunun 1.4.0-dan əvvəlki versiyalarında `restore_hidden_modules()` funksiyasında audit izlərini pozan logging səhvini və modul gizlətmə ilə import hook quraşdırması arasında race condition ehtiva edir. Bu, audit cədvəllərində sıfır bərpa edilmiş modul göstərilməsinə səbəb olur. İstifadəçilər 1.4.0 versiyasına yeniləmə etməlidirlər.
FAQ2
What versions of the 'openssl_encrypt' module are affected by CVE-2026-74885?
CVE-2026-74885 affects versions of the 'openssl_encrypt' module prior to 1.4.0.
How does CVE-2026-74885 affect audit trails?
A logging bug in the `restore_hidden_modules()` function shows zero restored modules in audit tables, corrupting audit trails.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.