VAITP Dataset

← Back to the dataset

CVE-2026-74887

Import of non-cryptographic 'random' module creates a future code hazard.

  • CVSS 9.3
  • 338
  • Cryptographic
  • Remote

openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import creates a hazard that future code could inadvertently use random.randint() instead of a cryptographically secure alternative (secrets/os.urandom), producing predictable values since the Mersenne Twister state can be recovered from approximately 624 outputs. Fixed by removing the import in 1.4.0.

CWE
338
CVSS base score
9.3
Published
2026-08-17
OWASP
A02 Cryptographic Failures
Orthogonal defect classification
Interface
Code defect classification
Extraneous Algorithm
Category
Cryptographic
Subcategory
Inadequate random number generation
Accessibility scope
Remote
Impact
Information Disclosure
Fixed by upgrading
Yes

Solution

Upgrade `openssl_encrypt` to version 1.4.0 or later.

Vulnerable code sample

# openssl_encrypt/modules/pqc.py

import os
import secrets
from cryptography.hazmat.primitives import hashes

# The real file had this import at line 15.
# Although unused, it creates a potential for misuse in a cryptographic context.
import random # VULNERABLE: Importing non-cryptographic 'random' module is a hazard for future code.

def generate_kyber_keypair():
    """
    Generates a new Kyber keypair.

    NOTE: This is a placeholder. A real implementation would use
    bindings to a PQC library like liboqs.
    """
    # In a real implementation, we would call a C library.
    # The key material should be sourced from a CSPRNG like secrets or os.urandom.
    # Note that the imported 'random' module is not used.
    private_key = secrets.token_bytes(32)
    public_key = secrets.token_bytes(32) # Simplified placeholder

    # Imagine some complex operations here that do not use 'random'.
    digest = hashes.Hash(hashes.SHA256())
    digest.update(public_key)
    digest.finalize()

    return (public_key, private_key)

Patched code sample

# openssl_encrypt/modules/pqc.py

import os
import secrets
from cryptography.hazmat.primitives import hashes

# The real file had this import at line 15.
# Although unused, it creates a potential for misuse in a cryptographic context.
# FIX: Removed import of non-cryptographic 'random' module to prevent accidental use.

def generate_kyber_keypair():
    """
    Generates a new Kyber keypair.

    NOTE: This is a placeholder. A real implementation would use
    bindings to a PQC library like liboqs.
    """
    # In a real implementation, we would call a C library.
    # The key material should be sourced from a CSPRNG like secrets or os.urandom.
    # Note that the imported 'random' module is not used.
    private_key = secrets.token_bytes(32)
    public_key = secrets.token_bytes(32) # Simplified placeholder

    # Imagine some complex operations here that do not use 'random'.
    digest = hashes.Hash(hashes.SHA256())
    digest.update(public_key)
    digest.finalize()

    return (public_key, private_key)

Cite this entry

@misc{vaitp:cve202674887,
  title        = {{Import of non-cryptographic 'random' module creates a future code hazard.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-74887},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-74887/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::