Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments. | |
| Title | openssl_encrypt before 1.4.0 Logging Bug and Race Condition | |
| Weaknesses | CWE-117 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-17T14:42:43.598Z
Reserved: 2026-08-17T10:36:18.506Z
Link: CVE-2026-74885
Updated: 2026-08-17T14:42:40.247Z
Status : Received
Published: 2026-08-17T11:16:43.260
Modified: 2026-08-17T15:16:58.797
Link: CVE-2026-74885
No data.
OpenCVE Enrichment
Updated: 2026-08-17T13:00:13Z
-
CWE-117
Improper Output Neutralization for Logs