UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, re

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

CVE-2026-74889Published 2 weeks agoUpdated 4 days agoSource: OSV

Affected packages

  • openssl-encryptbefore 1.4.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, re | HackTribune