VYPR

Openssl Encrypt

by Jahlives

Source repositories

CVEs (64)

  • CVE-2026-74877HigAug 17, 2026
    risk 0.57cvss 8.8epss 0.00

    openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the…

  • CVE-2026-74892HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.01

    openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.

  • CVE-2026-74888HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more…

  • CVE-2026-74884HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal…

  • CVE-2026-74882HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when…

  • CVE-2026-74879HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP…

  • CVE-2026-74874HigAug 17, 2026
    risk 0.49cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict…

  • CVE-2026-81683HigAug 27, 2026
    risk 0.48cvss 8.4epss 0.00

    openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker…

  • CVE-2026-81719HigAug 27, 2026
    risk 0.44cvss 7.8epss 0.00

    openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import time, before the runtime sandbox…

  • CVE-2026-81721HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.01

    openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large Argon2, scrypt, or balloon KDF…

  • CVE-2026-81718HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles or encrypted files can…

  • CVE-2026-81705HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer only recognized exact option names,…

  • CVE-2026-81704HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders…

  • CVE-2026-81699HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.01

    openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF…

  • CVE-2026-81698HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute…

  • CVE-2026-81693HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory…

  • CVE-2026-81691HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to…

  • CVE-2026-81689HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can precompute a single dictionary table and…

  • CVE-2026-81688HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or fingerprint identical plaintexts across separately-encrypted…

  • CVE-2026-74881MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.00

    openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.