Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments. | |
| Title | openssl_encrypt before 1.4.0 Logging Bug and Race Condition | |
| Weaknesses | CWE-117 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T11:04:50.459Z
Reserved: 2026-08-17T10:36:18.506Z
Link: CVE-2026-74885
No data.
Status : Received
Published: 2026-08-17T11:16:43.260
Modified: 2026-08-17T11:16:43.260
Link: CVE-2026-74885
No data.
OpenCVE Enrichment
No data.
-
CWE-117
Improper Output Neutralization for Logs