Schema Validation Bypass in OpenSSL Encrypt Affects Users
CVE-2026-74875

9.3CRITICAL

Key Information:

Vendor

Jahlives

Vendor
CVE Published:
17 August 2026

What is CVE-2026-74875?

In versions prior to 1.4.0, OpenSSL Encrypt fails to validate JSON schema when the jsonschema library is absent. This oversight permits attackers to manipulate and submit malformed metadata, potentially leading to exploitation. By removing the jsonschema package or introducing undefined metadata format versions, adversaries can bypass all schema checks, thus processing malicious data without detection.

Affected Version(s)

openssl_encrypt 0 < 1.4.0

openssl_encrypt 1.4.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.