CVE-2026-74888
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Aug 17, 2026
Vendor
unknown
Description
openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords protecting legacy encrypted files compared to standard PBKDF2 implementations.