Dependency scanning
Check whether openssl-encrypt is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-74881
openssl-encrypt has CORS wildcard with allow_credentials=True in standalone servers
CVE-2026-74871
CVE-2026-74871
CVE-2026-74881
CVE-2026-74881
CVE-2026-81689
CVE-2026-81689
CVE-2026-81694
CVE-2026-81694
CVE-2026-81715
CVE-2026-81715
CVE-2026-81680
CVE-2026-81680
CVE-2026-81704
CVE-2026-81704
CVE-2026-81699
CVE-2026-81699
CVE-2026-81702
CVE-2026-81702
CVE-2026-74870
CVE-2026-74870
CVE-2026-81684
CVE-2026-81684
CVE-2026-81720
CVE-2026-81720
CVE-2026-81717
CVE-2026-81717
CVE-2026-81688
CVE-2026-81688
CVE-2026-81714
CVE-2026-81714
CVE-2026-81719
CVE-2026-81719
CVE-2026-81683
CVE-2026-81683
CVE-2026-81721
CVE-2026-81721
CVE-2026-81681
CVE-2026-81681
CVE-2026-81691
CVE-2026-81691
CVE-2026-81693
CVE-2026-81693
CVE-2026-81690
CVE-2026-81690
CVE-2026-81716
CVE-2026-81716
CVE-2026-81685
CVE-2026-81685
CVE-2026-81686
CVE-2026-81686
CVE-2026-74880
openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage
CVE-2026-74873
openssl-encrypt has visible password in process list via --password CLI argument
CVE-2026-74878
openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restart
CVE-2026-74879
openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers
CVE-2026-74874
openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection
CVE-2026-74875
openssl-encrypt silently skips schema validation when jsonschema library is not installed
CVE-2026-74876
openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys
CVE-2026-74876
CVE-2026-74876
CVE-2026-74891
CVE-2026-74891
CVE-2026-74885
CVE-2026-74885
CVE-2026-81695
CVE-2026-81695
CVE-2026-74886
CVE-2026-74886
CVE-2026-81701
CVE-2026-81701
CVE-2026-74893
CVE-2026-74893
CVE-2026-81705
CVE-2026-81705
CVE-2026-74879
CVE-2026-74879
CVE-2026-81703
CVE-2026-81703
CVE-2026-74888
CVE-2026-74888
CVE-2026-74890
CVE-2026-74890
CVE-2026-74883
CVE-2026-74883
CVE-2026-74900
CVE-2026-74900
CVE-2026-81700
CVE-2026-81700
CVE-2026-81706
CVE-2026-81706
CVE-2026-74874
CVE-2026-74874
CVE-2026-74901
CVE-2026-74901
CVE-2026-74878
CVE-2026-74878
CVE-2026-81696
CVE-2026-81696
CVE-2026-74894
CVE-2026-74894
CVE-2026-74880
CVE-2026-74880
CVE-2026-74875
CVE-2026-74875
CVE-2026-74873
CVE-2026-74873
CVE-2026-74889
CVE-2026-74889
CVE-2026-81698
CVE-2026-81698
CVE-2026-74895
CVE-2026-74895
CVE-2026-74896
CVE-2026-74896
CVE-2026-74884
CVE-2026-74884
CVE-2026-74877
openssl-encrypt has no owner verification on key revocation — any client can revoke any key
CVE-2026-74872
openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification
CVE-2026-74887
CVE-2026-74887
CVE-2026-74877
CVE-2026-74877
CVE-2026-74882
CVE-2026-74882
CVE-2026-74892
CVE-2026-74892
CVE-2026-74872
CVE-2026-74872
CVE-2026-74899
CVE-2026-74899
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes