CVE-2026-74893

Source
https://cve.org/CVERecord?id=CVE-2026-74893
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74893.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74893
Aliases
  • GHSA-qc6h-gfjh-7qqg
Published
2026-08-17T11:04:55.855Z
Modified
2026-08-19T03:48:59.823829862Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
openssl_encrypt before 1.4.0 JWT Token Forgery via Hardcoded Secrets
Details

opensslencrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any clientid to gain authenticated access to keyserver and telemetry APIs.

Database specific
{
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74893.json",
    "cwe_ids": [
        "CWE-798"
    ]
}
References

Affected packages

Git / github.com/jahlives/openssl_encrypt

Affected ranges

Type
GIT
Repo
https://github.com/jahlives/openssl_encrypt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.4.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74893.json"