CVE-2026-74887
Import of non-cryptographic 'random' module creates a future code hazard.
- CVSS 9.3
- 338
- Cryptographic
- Remote
openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could inadvertently use random.randint() instead of a cryptographically secure alternative (secrets/os.urandom), producing predictable values since the Mersenne Twister state can be recovered from approximately 624 outputs. Fixed by removing the import in 1.4.0.
- CWE
- 338
- CVSS base score
- 9.3
- Published
- 2026-08-17
- OWASP
- A02 Cryptographic Failures
- Orthogonal defect classification
- Interface
- Code defect classification
- Extraneous Algorithm
- Category
- Cryptographic
- Subcategory
- Inadequate random number generation
- Accessibility scope
- Remote
- Impact
- Information Disclosure
- Fixed by upgrading
- Yes
Solution
Upgrade `openssl_encrypt` to version 1.4.0 or later.
Vulnerable code sample
# openssl_encrypt/modules/pqc.py
import os
import secrets
from cryptography.hazmat.primitives import hashes
# The real file had this import at line 15.
# Although unused, it creates a potential for misuse in a cryptographic context.
import random # VULNERABLE: Importing non-cryptographic 'random' module is a hazard for future code.
def generate_kyber_keypair():
"""
Generates a new Kyber keypair.
NOTE: This is a placeholder. A real implementation would use
bindings to a PQC library like liboqs.
"""
# In a real implementation, we would call a C library.
# The key material should be sourced from a CSPRNG like secrets or os.urandom.
# Note that the imported 'random' module is not used.
private_key = secrets.token_bytes(32)
public_key = secrets.token_bytes(32) # Simplified placeholder
# Imagine some complex operations here that do not use 'random'.
digest = hashes.Hash(hashes.SHA256())
digest.update(public_key)
digest.finalize()
return (public_key, private_key)Patched code sample
# openssl_encrypt/modules/pqc.py
import os
import secrets
from cryptography.hazmat.primitives import hashes
# The real file had this import at line 15.
# Although unused, it creates a potential for misuse in a cryptographic context.
# FIX: Removed import of non-cryptographic 'random' module to prevent accidental use.
def generate_kyber_keypair():
"""
Generates a new Kyber keypair.
NOTE: This is a placeholder. A real implementation would use
bindings to a PQC library like liboqs.
"""
# In a real implementation, we would call a C library.
# The key material should be sourced from a CSPRNG like secrets or os.urandom.
# Note that the imported 'random' module is not used.
private_key = secrets.token_bytes(32)
public_key = secrets.token_bytes(32) # Simplified placeholder
# Imagine some complex operations here that do not use 'random'.
digest = hashes.Hash(hashes.SHA256())
digest.update(public_key)
digest.finalize()
return (public_key, private_key)Cite this entry
@misc{vaitp:cve202674887,
title = {{Import of non-cryptographic 'random' module creates a future code hazard.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-74887},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-74887/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
