---
id: CVE-2026-74872
aliases:
  - GHSA-j48q-4c78-rhf9
title: >-
  openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern
  without integrity verification
summary: >-
  openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern
  without integrity verification
severity: medium
vendor: openssl-encrypt
product: openssl-encrypt
ecosystem: pip
affected:
  - openssl-encrypt < 1.4.0
patched:
  - openssl-encrypt 1.4.0
published: '2026-03-31'
updated: '2026-08-18'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-j48q-4c78-rhf9'
references:
  - url: >-
      https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-j48q-4c78-rhf9
  - url: >-
      https://github.com/jahlives/openssl_encrypt/commit/963d0d1278b722ea134272f9df65fddcd3e6ab47
  - url: 'https://github.com/jahlives/openssl_encrypt'
tags:
  - osv
  - pip
ingestedAt: '2026-08-18T12:28:09.078Z'
epss: 0.00679
epssPercentile: 0.50292
---

## Overview

## Severity: HIGH

### Summary

The Whirlpool hash implementation in `openssl_encrypt/modules/registry/hash_registry.py` at **lines 570-589** uses glob patterns to find `.so` modules in site-packages and loads the first match via `importlib` without verifying module integrity.

### Affected Code

```python
for site_pkg in site.getsitepackages():
    pattern = os.path.join(site_pkg, "whirlpool*py313*.so")
    py313_modules = glob.glob(pattern)
    if py313_modules:
        module_path = py313_modules[0]  # Takes first match
        loader = ExtensionFileLoader("whirlpool", module_path)
        spec = importlib.util.spec_from_file_location("whirlpool", module_path, loader=loader)
        whirlpool_module = importlib.util.module_from_spec(spec)
        spec.loader.exec_module(whirlpool_module)
```

### Impact

The glob pattern `"whirlpool*py313*.so"` is broad and takes the first match without verifying:
- File hash/signature
- File ownership/permissions
- Whether it's a legitimate module

If an attacker can place a malicious `.so` file matching this pattern in any site-packages directory, it will be loaded and native code executed.

### Recommended Fix

- Verify the module's integrity (hash or signature) before loading
- Use a specific filename rather than a glob pattern
- Check file permissions and ownership

### Fix

Fixed in commit `963d0d1` on branch `releases/1.4.x` — added os.path.realpath() to resolve symlinks and validation that found .so files are within known site-packages directories before loading.

## Affected packages

- `openssl-encrypt < 1.4.0`

## Remediation

Upgrade to a patched release:

- `openssl-encrypt 1.4.0`
