openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.
References
| Link | Resource |
|---|---|
| https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-2vhw-q7vh-7xv2 | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openssl-encrypt-before-information-disclosure-via-ready-endpoint | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-17 11:16
Updated : 2026-09-01 15:28
NVD link : CVE-2026-74879
Mitre link : CVE-2026-74879
CVE.ORG link : CVE-2026-74879
JSON object : View
Products Affected
jahlives
- openssl_encrypt
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
