CVE-2026-74887: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in jahlives openssl_encrypt
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could inadvertently use random.randint() instead of a cryptographically secure alternative (secrets/os.urandom), producing predictable values since the Mersenne Twister state can be recovered from approximately 624 outputs. Fixed by removing the import in 1.4.0.
AI Analysis
Technical Summary
The vulnerability involves the import of Python's non-cryptographic 'random' module (Mersenne Twister PRNG) in the openssl_encrypt module of jahlives before version 1.4.0. While the current code does not call random functions directly, the presence of this import creates a hazard that future code could mistakenly use random.randint() instead of a cryptographically secure PRNG like secrets or os.urandom. The Mersenne Twister PRNG is predictable because its internal state can be recovered from approximately 624 outputs. This vulnerability was addressed by removing the import in version 1.4.0.
Potential Impact
No direct cryptographic operations are currently affected, so immediate exploitation is not evident. However, the presence of the weak PRNG import increases the risk of future insecure code changes that could lead to predictable cryptographic values, potentially compromising security.
Mitigation Recommendations
Upgrade to jahlives openssl_encrypt version 1.4.0 or later, where the insecure import of the non-cryptographic random module has been removed. This eliminates the hazard of inadvertently using a weak PRNG.
CVE-2026-74887: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in jahlives openssl_encrypt
Description
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could inadvertently use random.randint() instead of a cryptographically secure alternative (secrets/os.urandom), producing predictable values since the Mersenne Twister state can be recovered from approximately 624 outputs. Fixed by removing the import in 1.4.0.
CVSS v4.0
Score 6.3medium
Affected software
jahlives
openssl_encrypt
pkg:github/jahlives/openssl_encryptRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves the import of Python's non-cryptographic 'random' module (Mersenne Twister PRNG) in the openssl_encrypt module of jahlives before version 1.4.0. While the current code does not call random functions directly, the presence of this import creates a hazard that future code could mistakenly use random.randint() instead of a cryptographically secure PRNG like secrets or os.urandom. The Mersenne Twister PRNG is predictable because its internal state can be recovered from approximately 624 outputs. This vulnerability was addressed by removing the import in version 1.4.0.
Potential Impact
No direct cryptographic operations are currently affected, so immediate exploitation is not evident. However, the presence of the weak PRNG import increases the risk of future insecure code changes that could lead to predictable cryptographic values, potentially compromising security.
Mitigation Recommendations
Upgrade to jahlives openssl_encrypt version 1.4.0 or later, where the insecure import of the non-cryptographic random module has been removed. This eliminates the hazard of inadvertently using a weak PRNG.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-17T10:42:40.455Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a82f004bf8831d539c48362
Added to database: 08/17/2026, 11:27:00 UTC
Last enriched: 09/12/2026, 01:49:06 UTC
Last updated: 10/01/2026, 15:31:50 UTC
Views: 59
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.