What is CVE-2026-74900?
CVE-2026-74900 is a critical vulnerability in openssl_encrypt versions before 1.4.0. It allows KEM decapsulation failures in pqc.py to silently fall back to simulation mode, generating a deterministic shared secret from just 16 bytes of the private key. Affected users should immediately upgrade to version 1.4.0 or later.
Azərbaycanca: CVE-2026-74900 openssl_encrypt-in 1.4.0-dən əvvəlki versiyalarında kritik zəiflikdir. pqc.py-də KEM dekapsulyasiya xətası simulyasiya rejiminə keçid edir və yalnız 16 baytlıq private key ilə müəyyən olunan paylaşılan sirri yaradır. Təsirə məruz qalan sistemləri dərhal 1.4.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of openssl_encrypt are affected by CVE-2026-74900?
This vulnerability affects openssl_encrypt versions prior to 1.4.0.
What is the result of the KEM decapsulation failure in CVE-2026-74900?
The KEM decapsulation failure silently falls back to simulation mode, generating a deterministic shared secret from just 16 bytes of the private key.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.