Token Leakage Vulnerability in OpenSSL_encrypt Prior to Version 1.4.0
CVE-2026-74880

9.3CRITICAL

Key Information:

Vendor

Jahlives

Vendor
CVE Published:
17 August 2026

What is CVE-2026-74880?

The openssl_encrypt library versions prior to 1.4.0 are susceptible to a token leakage vulnerability due to improper handling of refresh tokens within URL query parameters. This weakness affects keyserver and telemetry server routes, allowing attackers to extract sensitive tokens from server logs, proxy logs, browser history, and HTTP Referer headers. Consequently, unauthorized parties can gain access to protected resources, posing a significant security risk to affected applications.

Affected Version(s)

openssl_encrypt 0 < 1.4.0

openssl_encrypt 1.4.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.