CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-74889 — openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info para...

·Source: NIST NVD

Updated:

Executive Summary

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

Analysis

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks. CVSS Score: 9.8. Published: 2026-08-17T11:16:43.803.

Indicators of Compromise (1)

CVE (1)
CVE-2026-74889
Source Attribution

Originally published by NIST NVD on Aug 17, 2026. Verified by: NIST.

Related Threats