Disclosure summary
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
Source-reported weakness categories
CWE-345
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-74875
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| jahlives | openssl_encrypt | * {"versionEndExcluding":"1.4.0"} |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Mitigation, Vendor Advisory
- www.vulncheck.com — Third Party Advisory
PUBLISHED 2026-08-17T07:16:41-04:00
MODIFIED 2026-10-08T12:17:39-04:00
INGESTED 2026-10-10T20:50:36-04:00