Vulnerability Bulletins |
CVE-2026-74888 |
|
| Affected software | OPENSSL |
| openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords protecting legacy encrypted files compared to standard PBKDF2 implementations. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-74888 | |






