<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:39:55 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-74872 — openssl_encrypt before 1.4.0 Arbitrary Code Execution via Whirlpool</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-74872</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; jahlives openssl_encrypt&lt;/p&gt;
&lt;p&gt;openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; jahlives openssl_encrypt&lt;/p&gt;
&lt;p&gt;openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-74872</guid>
    </item>
    <item>
      <title>GHSA-j48q-4c78-rhf9 — openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j48q-4c78-rhf9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openssl-encrypt&lt;/p&gt;
&lt;p&gt;## Severity: HIGH&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Whirlpool hash implementation in `openssl_encrypt/modules/registry/hash_registry.py` at **lines 570-589** uses glob patterns to find `.so` modules in site-packages and loads the first match via `importlib` without verifying module integrity.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;```python
for site_pkg in site.getsitepackages():
    pattern = os.path.join(site_pkg, &amp;#34;whirlpool*py313*.so&amp;#34;)
    py313_modules = glob.glob(pattern)
    if py313_modules:
        module_path = py313_modules[0]  # Takes first match
        loader = ExtensionFileLoader(&amp;#34;whirlpool&amp;#34;, module_path)
        spec = importlib.util.spec_from_file_location(&amp;#34;whirlpool&amp;#34;, module_path, loader=loader)
        whirlpool_module = importlib.util.module_from_spec(spec)
        spec.loader.exec_module(whirlpool_module)
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The glob pattern `&amp;#34;whirlpool*py313*.so&amp;#34;` is broad and takes the first match without verifying:
- File hash/signature
- File ownership/permissions
- Whether it&amp;#39;s a legitimate module&lt;/p&gt;
&lt;p&gt;If an attacker can place a malicious `.so` file matching this pattern in any site-packages directory, it will be loaded and native code executed.&lt;/p&gt;
&lt;p&gt;### Recommended Fix&lt;/p&gt;
&lt;p&gt;- Verify the module&amp;#39;s integrity (hash or signature) before loading
- Use a specific filename rather than a glob pattern
- Check file permissions and ownership&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;Fixed in commit `963d0d1` on branch `releases/1.4.x` — added os.path.realpath() to resolve symlinks and validation that found .so files are within known site-pac…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openssl-encrypt&lt;/p&gt;
&lt;p&gt;## Severity: HIGH&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Whirlpool hash implementation in `openssl_encrypt/modules/registry/hash_registry.py` at **lines 570-589** uses glob patterns to find `.so` modules in site-packages and loads the first match via `importlib` without verifying module integrity.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;```python
for site_pkg in site.getsitepackages():
    pattern = os.path.join(site_pkg, &amp;#34;whirlpool*py313*.so&amp;#34;)
    py313_modules = glob.glob(pattern)
    if py313_modules:
        module_path = py313_modules[0]  # Takes first match
        loader = ExtensionFileLoader(&amp;#34;whirlpool&amp;#34;, module_path)
        spec = importlib.util.spec_from_file_location(&amp;#34;whirlpool&amp;#34;, module_path, loader=loader)
        whirlpool_module = importlib.util.module_from_spec(spec)
        spec.loader.exec_module(whirlpool_module)
```&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The glob pattern `&amp;#34;whirlpool*py313*.so&amp;#34;` is broad and takes the first match without verifying:
- File hash/signature
- File ownership/permissions
- Whether it&amp;#39;s a legitimate module&lt;/p&gt;
&lt;p&gt;If an attacker can place a malicious `.so` file matching this pattern in any site-packages directory, it will be loaded and native code executed.&lt;/p&gt;
&lt;p&gt;### Recommended Fix&lt;/p&gt;
&lt;p&gt;- Verify the module&amp;#39;s integrity (hash or signature) before loading
- Use a specific filename rather than a glob pattern
- Check file permissions and ownership&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;Fixed in commit `963d0d1` on branch `releases/1.4.x` — added os.path.realpath() to resolve symlinks and validation that found .so files are within known site-pac…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j48q-4c78-rhf9</guid>
    </item>
  </channel>
</rss>
