Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-74874

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 16.8%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-74874


Contact Us

Shodan ® - All rights reserved