<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:38:26.655566+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-74872</id>
    <title>CVE-2026-74872 — openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool</title>
    <updated>2026-10-02T18:38:26.686078+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> jahlives openssl_encrypt</p>
<p>openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-74872"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j48q-4c78-rhf9</id>
    <title>GHSA-j48q-4c78-rhf9 — openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification</title>
    <updated>2026-10-02T18:38:26.686138+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: openssl-encrypt</p>
<p>## Severity: HIGH</p>
<p>### Summary</p>
<p>The Whirlpool hash implementation in `openssl_encrypt/modules/registry/hash_registry.py` at **lines 570-589** uses glob patterns to find `.so` modules in site-packages and loads the first match via `importlib` without verifying module integrity.</p>
<p>### Affected Code</p>
<p>```python
for site_pkg in site.getsitepackages():
    pattern = os.path.join(site_pkg, "whirlpool*py313*.so")
    py313_modules = glob.glob(pattern)
    if py313_modules:
        module_path = py313_modules[0]  # Takes first match
        loader = ExtensionFileLoader("whirlpool", module_path)
        spec = importlib.util.spec_from_file_location("whirlpool", module_path, loader=loader)
        whirlpool_module = importlib.util.module_from_spec(spec)
        spec.loader.exec_module(whirlpool_module)
```</p>
<p>### Impact</p>
<p>The glob pattern `"whirlpool*py313*.so"` is broad and takes the first match without verifying:
- File hash/signature
- File ownership/permissions
- Whether it's a legitimate module</p>
<p>If an attacker can place a malicious `.so` file matching this pattern in any site-packages directory, it will be loaded and native code executed.</p>
<p>### Recommended Fix</p>
<p>- Verify the module's integrity (hash or signature) before loading
- Use a specific filename rather than a glob pattern
- Check file permissions and ownership</p>
<p>### Fix</p>
<p>Fixed in commit `963d0d1` on branch `releases/1.4.x` — added os.path.realpath() to resolve symlinks and validation that found .so files are within known site-pac…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j48q-4c78-rhf9"/>
  </entry>
</feed>
