<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T16:27:37.744004+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-74876</id>
    <title>CVE-2026-74876 — openssl_encrypt before 1.4.0 Unverified Key Bundle Encryption</title>
    <updated>2026-10-05T16:27:37.777047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> jahlives openssl_encrypt</p>
<p>openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-74876"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8h88-gxp3-j7pg</id>
    <title>GHSA-8h88-gxp3-j7pg — openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys</title>
    <updated>2026-10-05T16:27:37.777132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: openssl-encrypt</p>
<p>### Summary</p>
<p>The `PublicKeyBundle.from_dict()` method in `openssl_encrypt/modules/key_bundle.py` at **lines 329-361** creates bundles from untrusted data without verifying the signature. The docstring warns to call `verify_signature()` after creation, but the `to_identity()` method (line 363-391) can convert an unverified bundle directly to an `Identity` object.</p>
<p>### Affected Code</p>
<p>```python
@classmethod
def from_dict(cls, data: Dict) -&gt; "PublicKeyBundle":
    """
    SECURITY: Does NOT verify signature. Call verify_signature() after creation.
    """
    # Creates bundle without verification
```</p>
<p>### Impact</p>
<p>If `from_dict()` followed by `to_identity()` is called without an intervening `verify_signature()` call, encryption could be performed against an attacker's public key, leaking secrets. While `key_resolver.py` (lines 146-147) does verify before use, the unguarded API path remains directly callable.</p>
<p>### Recommended Fix</p>
<p>- Add a `verified` flag to `PublicKeyBundle` that must be set before `to_identity()` can be called
- Or have `to_identity()` automatically call `verify_signature()` and raise on failure
- Or make `from_dict()` require verification as part of construction</p>
<p>### Fix</p>
<p>Fixed in commit `f4a1ba6` on branch `releases/1.4.x` — from_dict() now verifies self_signature by default (verify=True parameter); raises ValueError on verification failure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8h88-gxp3-j7pg"/>
  </entry>
</feed>
