Token Leakage Vulnerability in OpenSSL_encrypt Prior to Version 1.4.0
CVE-2026-74880
9.3CRITICAL
What is CVE-2026-74880?
The openssl_encrypt library versions prior to 1.4.0 are susceptible to a token leakage vulnerability due to improper handling of refresh tokens within URL query parameters. This weakness affects keyserver and telemetry server routes, allowing attackers to extract sensitive tokens from server logs, proxy logs, browser history, and HTTP Referer headers. Consequently, unauthorized parties can gain access to protected resources, posing a significant security risk to affected applications.
Affected Version(s)
openssl_encrypt 0 < 1.4.0
openssl_encrypt 1.4.0
