<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:00:51 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-74874 — openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-74874</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; jahlives openssl_encrypt&lt;/p&gt;
&lt;p&gt;openssl_encrypt versions before 1.4.0 use Python&amp;#39;s non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; jahlives openssl_encrypt&lt;/p&gt;
&lt;p&gt;openssl_encrypt versions before 1.4.0 use Python&amp;#39;s non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-74874</guid>
    </item>
    <item>
      <title>GHSA-vfgx-5q85-58q3 — openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vfgx-5q85-58q3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openssl-encrypt&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `generate_pseudorandom_sequence()` function in `openssl_encrypt/plugins/steganography/core/utils.py` at **lines 89-91** uses Python&amp;#39;s `random` module (Mersenne Twister) for steganographic pixel/sample selection.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;```python
random.seed(seed)
sequence = random.sample(range(max_value), min(length, max_value))
return sequence
```&lt;/p&gt;
&lt;p&gt;Additionally, the steganography password is stored as a plain Python string (not `SecureBytes`) and only 8 bytes (64 bits) of the SHA-256 hash are used for the seed, reducing effective security to 64 bits.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The Mersenne Twister&amp;#39;s state can be recovered from approximately 624 outputs. An attacker who knows or guesses the password can predict the PRNG sequence and determine exactly which pixels contain hidden data, potentially extracting the hidden data without the password.&lt;/p&gt;
&lt;p&gt;### Recommended Fix&lt;/p&gt;
&lt;p&gt;- Use HMAC-DRBG or `secrets` module for cryptographically secure pixel selection
- Use full 32-byte SHA-256 output as seed material
- Store the password in `SecureBytes` instead of a plain string&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;Fixed in commit `09e96e0` on branch `releases/1.4.x` — replaced random.seed(hash(password)) with HMAC-SHA256 based CSPRNG (Fisher-Yates shuffle) and numpy Generator with HMAC-derived seeds across all steganography format modules.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: openssl-encrypt&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `generate_pseudorandom_sequence()` function in `openssl_encrypt/plugins/steganography/core/utils.py` at **lines 89-91** uses Python&amp;#39;s `random` module (Mersenne Twister) for steganographic pixel/sample selection.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;```python
random.seed(seed)
sequence = random.sample(range(max_value), min(length, max_value))
return sequence
```&lt;/p&gt;
&lt;p&gt;Additionally, the steganography password is stored as a plain Python string (not `SecureBytes`) and only 8 bytes (64 bits) of the SHA-256 hash are used for the seed, reducing effective security to 64 bits.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The Mersenne Twister&amp;#39;s state can be recovered from approximately 624 outputs. An attacker who knows or guesses the password can predict the PRNG sequence and determine exactly which pixels contain hidden data, potentially extracting the hidden data without the password.&lt;/p&gt;
&lt;p&gt;### Recommended Fix&lt;/p&gt;
&lt;p&gt;- Use HMAC-DRBG or `secrets` module for cryptographically secure pixel selection
- Use full 32-byte SHA-256 output as seed material
- Store the password in `SecureBytes` instead of a plain string&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;Fixed in commit `09e96e0` on branch `releases/1.4.x` — replaced random.seed(hash(password)) with HMAC-SHA256 based CSPRNG (Fisher-Yates shuffle) and numpy Generator with HMAC-derived seeds across all steganography format modules.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vfgx-5q85-58q3</guid>
    </item>
  </channel>
</rss>
