Schema Validation Bypass in OpenSSL Encrypt Affects Users
CVE-2026-74875
9.3CRITICAL
What is CVE-2026-74875?
In versions prior to 1.4.0, OpenSSL Encrypt fails to validate JSON schema when the jsonschema library is absent. This oversight permits attackers to manipulate and submit malformed metadata, potentially leading to exploitation. By removing the jsonschema package or introducing undefined metadata format versions, adversaries can bypass all schema checks, thus processing malicious data without detection.
Affected Version(s)
openssl_encrypt 0 < 1.4.0
openssl_encrypt 1.4.0
