UNKNOWNPyPI

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.

CVE-2026-74894Published 2 weeks agoUpdated 4 days agoSource: OSV

Affected packages

  • openssl-encryptbefore 1.4.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep | HackTribune