CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-74872 — openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulner...

·Source: NIST NVD

Updated:

Executive Summary

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.

Analysis

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded. CVSS Score: 9.8. Published: 2026-08-17T11:16:41.560.

Indicators of Compromise (1)

CVE (1)
CVE-2026-74872
Source Attribution

Originally published by NIST NVD on Aug 17, 2026. Verified by: NIST.

Related Threats