{"id":"CVE-2026-74885","aliases":["GHSA-43r4-3hf9-m84q"],"url":"https://o3.security/vulnerability/CVE-2026-74885","summary":"openssl_encrypt before 1.4.0 Logging Bug and Race Condition","details":"openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.","published":"2026-08-17T11:04:50.459Z","modified":"2026-08-18T03:56:31.485073786Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74885.json"},{"type":"ADVISORY","url":"https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-43r4-3hf9-m84q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74885"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openssl-encrypt-before-logging-bug-and-race-condition"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T03:56:31.485073786Z"}}