Search found 257 matches

by Starburst-David
Thu Aug 27, 2026 8:48 pm
Forum: CVE Advisories
Topic: CVE-2026-81721 - openssl_encrypt before 1.4.9 Denial of Service via KDF
Replies: 0
Views: 10

CVE-2026-81721 - openssl_encrypt before 1.4.9 Denial of Service via KDF

CVE ID :CVE-2026-81721
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious ...
by Starburst-David
Thu Aug 27, 2026 8:47 pm
Forum: CVE Advisories
Topic: CVE-2026-81720 - openssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2
Replies: 0
Views: 5

CVE-2026-81720 - openssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2

CVE ID :CVE-2026-81720
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write ...
by Starburst-David
Thu Aug 27, 2026 8:47 pm
Forum: CVE Advisories
Topic: CVE-2026-81719 - openssl_encrypt before 1.4.9 Remote Code Execution via Plugin
Replies: 0
Views: 5

CVE-2026-81719 - openssl_encrypt before 1.4.9 Remote Code Execution via Plugin

CVE ID :CVE-2026-81719
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and ...
by Starburst-David
Thu Aug 27, 2026 8:46 pm
Forum: CVE Advisories
Topic: CVE-2026-81718 - openssl_encrypt before 1.4.9 Weak Cryptographic Parameters
Replies: 0
Views: 5

CVE-2026-81718 - openssl_encrypt before 1.4.9 Weak Cryptographic Parameters

CVE ID :CVE-2026-81718
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password ...
by Starburst-David
Thu Aug 27, 2026 8:45 pm
Forum: CVE Advisories
Topic: CVE-2026-81717 - openssl_encrypt before 1.4.9 Integrity Bypass via Added Files
Replies: 0
Views: 5

CVE-2026-81717 - openssl_encrypt before 1.4.9 Integrity Bypass via Added Files

CVE ID :CVE-2026-81717
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write ...
by Starburst-David
Thu Aug 27, 2026 8:44 pm
Forum: CVE Advisories
Topic: CVE-2026-81716 - openssl_encrypt before 1.4.9 Plugin Sandbox Path Traversal
Replies: 0
Views: 4

CVE-2026-81716 - openssl_encrypt before 1.4.9 Plugin Sandbox Path Traversal

CVE ID :CVE-2026-81716
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin ...
by Starburst-David
Thu Aug 27, 2026 8:43 pm
Forum: CVE Advisories
Topic: CVE-2026-81715 - openssl_encrypt before 1.4.9 Credential Exposure via Debug Output
Replies: 0
Views: 4

CVE-2026-81715 - openssl_encrypt before 1.4.9 Credential Exposure via Debug Output

CVE ID :CVE-2026-81715
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize ...
by Starburst-David
Thu Aug 27, 2026 8:43 pm
Forum: CVE Advisories
Topic: CVE-2026-81714 - openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass
Replies: 0
Views: 5

CVE-2026-81714 - openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass

CVE ID :CVE-2026-81714
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32 ...
by Starburst-David
Thu Aug 27, 2026 8:42 pm
Forum: CVE Advisories
Topic: CVE-2026-81706 - openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing
Replies: 0
Views: 5

CVE-2026-81706 - openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing

CVE ID :CVE-2026-81706
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding ...
by Starburst-David
Thu Aug 27, 2026 8:42 pm
Forum: CVE Advisories
Topic: CVE-2026-81705 - openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug
Replies: 0
Views: 5

CVE-2026-81705 - openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug

CVE ID :CVE-2026-81705
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e ...

Go to advanced search