CVE-2026-74886
opensslencrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUSMODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74886.json, https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-9pgj-v69p-q586, https://nvd.nist.gov/vuln/detail/CVE-2026-74886, https://www.vulncheck.com/advisories/openssl-encrypt-before-plugin-import-guard-bypass