CVE ID :CVE-2026-81721
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious ...
Search found 257 matches
- Thu Aug 27, 2026 8:48 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81721 - openssl_encrypt before 1.4.9 Denial of Service via KDF
- Replies: 0
- Views: 10
- Thu Aug 27, 2026 8:47 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81720 - openssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2
- Replies: 0
- Views: 5
CVE-2026-81720 - openssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2
CVE ID :CVE-2026-81720
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write ...
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write ...
- Thu Aug 27, 2026 8:47 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81719 - openssl_encrypt before 1.4.9 Remote Code Execution via Plugin
- Replies: 0
- Views: 5
CVE-2026-81719 - openssl_encrypt before 1.4.9 Remote Code Execution via Plugin
CVE ID :CVE-2026-81719
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and ...
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and ...
- Thu Aug 27, 2026 8:46 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81718 - openssl_encrypt before 1.4.9 Weak Cryptographic Parameters
- Replies: 0
- Views: 5
CVE-2026-81718 - openssl_encrypt before 1.4.9 Weak Cryptographic Parameters
CVE ID :CVE-2026-81718
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password ...
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password ...
- Thu Aug 27, 2026 8:45 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81717 - openssl_encrypt before 1.4.9 Integrity Bypass via Added Files
- Replies: 0
- Views: 5
CVE-2026-81717 - openssl_encrypt before 1.4.9 Integrity Bypass via Added Files
CVE ID :CVE-2026-81717
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write ...
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write ...
- Thu Aug 27, 2026 8:44 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81716 - openssl_encrypt before 1.4.9 Plugin Sandbox Path Traversal
- Replies: 0
- Views: 4
CVE-2026-81716 - openssl_encrypt before 1.4.9 Plugin Sandbox Path Traversal
CVE ID :CVE-2026-81716
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin ...
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin ...
- Thu Aug 27, 2026 8:43 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81715 - openssl_encrypt before 1.4.9 Credential Exposure via Debug Output
- Replies: 0
- Views: 4
CVE-2026-81715 - openssl_encrypt before 1.4.9 Credential Exposure via Debug Output
CVE ID :CVE-2026-81715
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize ...
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize ...
- Thu Aug 27, 2026 8:43 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81714 - openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass
- Replies: 0
- Views: 5
CVE-2026-81714 - openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass
CVE ID :CVE-2026-81714
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32 ...
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32 ...
- Thu Aug 27, 2026 8:42 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81706 - openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing
- Replies: 0
- Views: 5
CVE-2026-81706 - openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing
CVE ID :CVE-2026-81706
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding ...
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding ...
- Thu Aug 27, 2026 8:42 pm
- Forum: CVE Advisories
- Topic: CVE-2026-81705 - openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug
- Replies: 0
- Views: 5
CVE-2026-81705 - openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug
CVE ID :CVE-2026-81705
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e ...
Published : Aug. 27, 2026, 5:21 p.m. | 48 minutes ago
Description :openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e ...