CVE-2026-74880: Use of GET Request Method With Sensitive Query Strings in jahlives openssl_encrypt
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
AI Analysis
Technical Summary
The vulnerability CVE-2026-74880 affects jahlives' openssl_encrypt component prior to version 1.4.0. It involves the use of HTTP GET requests that include sensitive refresh tokens as URL query parameters in keyserver and telemetry server routes. Because these tokens appear in URLs, they can be inadvertently logged or exposed in various places such as server logs, proxy logs, browser history, and HTTP Referer headers. This exposure can be leveraged by attackers to gain unauthorized access to systems or data protected by these tokens. The CVSS 4.0 score is 9.3, indicating a critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
Attackers can obtain sensitive refresh tokens by intercepting or accessing logs and browser histories where these tokens are exposed in URL query strings. This exposure can lead to unauthorized access to protected resources or systems, compromising confidentiality, integrity, and availability of the affected services.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using versions prior to 1.4.0 that accept sensitive tokens in URL query parameters. Consider redesigning the application to transmit sensitive tokens via POST requests or secure headers rather than in URLs to prevent token leakage through logs and browser history.
CVE-2026-74880: Use of GET Request Method With Sensitive Query Strings in jahlives openssl_encrypt
Description
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
CVSS v4.0
Score 9.3critical
Affected software
jahlives
openssl_encrypt
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-74880 affects jahlives' openssl_encrypt component prior to version 1.4.0. It involves the use of HTTP GET requests that include sensitive refresh tokens as URL query parameters in keyserver and telemetry server routes. Because these tokens appear in URLs, they can be inadvertently logged or exposed in various places such as server logs, proxy logs, browser history, and HTTP Referer headers. This exposure can be leveraged by attackers to gain unauthorized access to systems or data protected by these tokens. The CVSS 4.0 score is 9.3, indicating a critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
Attackers can obtain sensitive refresh tokens by intercepting or accessing logs and browser histories where these tokens are exposed in URL query strings. This exposure can lead to unauthorized access to protected resources or systems, compromising confidentiality, integrity, and availability of the affected services.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using versions prior to 1.4.0 that accept sensitive tokens in URL query parameters. Consider redesigning the application to transmit sensitive tokens via POST requests or secure headers rather than in URLs to prevent token leakage through logs and browser history.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-17T10:36:18.505Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a82f003bf8831d539c4831e
Added to database: 08/17/2026, 11:26:59 UTC
Last enriched: 08/24/2026, 13:33:37 UTC
Last updated: 10/02/2026, 02:46:06 UTC
Views: 43
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.