CVE-2026-81705
- EPSS 0.33%
- Veröffentlicht 27.08.2026 14:51:07
- Zuletzt bearbeitet 01.09.2026 17:59:54
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only recogni...
CVE-2026-81704
- EPSS 0.2%
- Veröffentlicht 27.08.2026 14:51:06
- Zuletzt bearbeitet 03.09.2026 15:09:32
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted file...
CVE-2026-81703
- EPSS 0.17%
- Veröffentlicht 27.08.2026 14:51:06
- Zuletzt bearbeitet 01.09.2026 18:11:14
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication an...
CVE-2026-81702
- EPSS 0.14%
- Veröffentlicht 27.08.2026 14:51:05
- Zuletzt bearbeitet 03.09.2026 15:09:14
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while m...
CVE-2026-81700
- EPSS 0.25%
- Veröffentlicht 27.08.2026 14:51:04
- Zuletzt bearbeitet 01.09.2026 18:13:59
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Atta...
CVE-2026-81701
- EPSS 0.31%
- Veröffentlicht 27.08.2026 14:51:04
- Zuletzt bearbeitet 01.09.2026 18:12:15
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned...
CVE-2026-81699
- EPSS 0.35%
- Veröffentlicht 27.08.2026 14:51:03
- Zuletzt bearbeitet 03.09.2026 15:09:04
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious fil...
CVE-2026-81698
- EPSS 0.28%
- Veröffentlicht 27.08.2026 14:51:02
- Zuletzt bearbeitet 01.09.2026 18:16:56
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing s...
CVE-2026-81697
- EPSS 0.15%
- Veröffentlicht 27.08.2026 14:51:00
- Zuletzt bearbeitet 23.09.2026 17:17:42
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is reassigned at line 84 ...
CVE-2026-81696
- EPSS 0.18%
- Veröffentlicht 27.08.2026 14:50:59
- Zuletzt bearbeitet 01.09.2026 20:21:05
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification informa...