{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openssl_encrypt--1.4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-74893"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["openssl_encrypt (\u003c 1.4.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe openssl_encrypt Python library, specifically versions prior to 1.4.0, contains hardcoded default JWT signing secrets within the 'config.py' file. This flaw allows attackers to derive the secret used for signing authentication tokens. By leveraging the known secret, an unauthorized actor can forge valid JWT tokens for any client_id. Successfully forging these tokens grants the attacker authenticated access to sensitive backend services, including keyserver and telemetry APIs, bypassing standard identity and access management controls. This vulnerability (CVE-2026-74893) is classified as a 'Use of Hard-coded Credentials' (CWE-798) and requires immediate remediation by upgrading to version 1.4.0 or higher.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to systems utilizing openssl_encrypt for authentication or telemetry data processing. Unauthorized access via forged tokens could result in the exfiltration of sensitive telemetry data, compromise of cryptographic keys handled by the keyserver API, and full identity impersonation within the application environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'openssl_encrypt' package to version 1.4.0 or later immediately to remove the hardcoded secret.\u003c/li\u003e\n\u003cli\u003eReview all JWT tokens issued or validated by applications using 'openssl_encrypt' prior to the upgrade for signs of suspicious or unauthorized client_id generation.\u003c/li\u003e\n\u003cli\u003eRotate all secrets and cryptographic material associated with the affected keyserver and telemetry APIs if there is evidence that the hardcoded secret was exposed or exploited.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-17T12:50:36Z","date_published":"2026-08-17T12:50:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-openssl-encrypt-jwt-vuln/","summary":"The openssl_encrypt library versions before 1.4.0 contain hardcoded JWT signing secrets that allow for arbitrary token forgery and unauthorized API access.","title":"Hardcoded JWT Signing Secrets in openssl_encrypt","url":"https://feed.craftedsignal.io/briefs/2026-08-openssl-encrypt-jwt-vuln/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-74872"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["openssl_encrypt (\u003c 1.4.0)","openssl_encrypt"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","python","supply-chain","library-vulnerability","cryptography","cve-2026-74876","authentication-bypass","totp","brute-force","cve-2026-74894","cwe-338","sandbox-bypass","cve-2026-74883"],"_cs_type":"advisory","_cs_vendors":["jahlives"],"content_html":"\u003cp\u003eThe openssl_encrypt Python package, specifically versions prior to 1.4.0, contains an arbitrary code execution vulnerability (CVE-2026-74872) located within its Whirlpool hash implementation. The library attempts to load shared object (.so) modules using overly broad glob patterns without performing any integrity or authenticity checks. An attacker capable of writing files to the Python site-packages directory can place a malicious shared object file that matches the pattern 'whirlpool\u003cem\u003epy313\u003c/em\u003e.so'. When the openssl_encrypt library is imported or the specific hash function is invoked, the Python interpreter loads the malicious .so file, resulting in native code execution under the context of the running process. This issue is categorized as CWE-426: Untrusted Search Path.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 score of 9.8 (Critical). Successful exploitation allows unauthenticated remote or local attackers to achieve arbitrary code execution on systems where the library is present and the site-packages directory is writable. This exposes applications to full system compromise, data theft, and persistence, particularly in environments where automated installers or CI/CD pipelines might inadvertently grant attackers write access to site-packages.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'openssl_encrypt' package to version 1.4.0 or later across all Python environments.\u003c/li\u003e\n\u003cli\u003eAudit existing Python site-packages directories for any files matching the pattern 'whirlpool\u003cem\u003epy313\u003c/em\u003e.so' that were not installed by the official package manager.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring on Python library installation paths to detect unauthorized creation of .so files.\u003c/li\u003e\n\u003cli\u003eEnforce strict file system permissions on 'site-packages' directories to prevent non-privileged users from modifying or adding library files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-17T12:50:26Z","date_published":"2026-08-17T12:46:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-openssl-encrypt-rce/","summary":"The openssl_encrypt library before version 1.4.0 contains a vulnerability in its Whirlpool hash implementation that allows arbitrary code execution via untrusted shared object loading.","title":"Arbitrary Code Execution in openssl_encrypt Library","url":"https://feed.craftedsignal.io/briefs/2026-08-openssl-encrypt-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Openssl_encrypt (\u003c 1.4.0)","version":"https://jsonfeed.org/version/1.1"}