CVE-2026-74893
jahlives openssl_encrypt
Published 17 Aug 2026 · updated 1 Sept 2026 · Analyzed
8.7 High · CVSS 4.0, vulncheck.com
Description
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs.
References
- github.com/jahlives/openssl_encrypt/security/advisories/GHSA-qc6h-gfjh-7qqg · Mitigation, Vendor Advisory
- www.vulncheck.com/advisories/openssl-encrypt-before-jwt-token-forgery-via-hardcoded-secrets · Third Party Advisory