VYPR

Openssl Encrypt

by Jahlives

Source repositories

CVEs (65)

  • CVE-2026-74881MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.00

    openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.

  • CVE-2026-81690HigAug 27, 2026
    risk 0.40cvss 7.3epss 0.00

    openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treats the symlink as an ordinary directory,…

  • CVE-2026-74871MedAug 17, 2026
    risk 0.40cvss 6.2epss 0.00

    openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and…

  • CVE-2026-81714HigAug 27, 2026
    risk 0.39cvss 7.0epss 0.00

    openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG key id could unknowingly enroll an attacker's colliding key…

  • CVE-2026-81706MedAug 27, 2026
    risk 0.37cvss 6.8epss 0.00

    openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the…

  • CVE-2026-74890MedAug 17, 2026
    risk 0.36cvss 5.5epss 0.00

    openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to…

  • CVE-2026-74873MedAug 17, 2026
    risk 0.36cvss 5.5epss 0.00

    openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.

  • CVE-2026-81720MedAug 27, 2026
    risk 0.33cvss 6.2epss 0.00

    openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files…

  • CVE-2026-81686MedAug 27, 2026
    risk 0.33cvss 6.2epss 0.00

    openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user on the system bus can call Set without authorization and set…

  • CVE-2026-81684MedAug 27, 2026
    risk 0.33cvss 6.2epss 0.00

    In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and decrypt paths) instead of via an environment variable as done…

  • CVE-2026-81682MedAug 27, 2026
    risk 0.33cvss 6.2epss 0.00

    openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on…

  • CVE-2026-81703MedAug 27, 2026
    risk 0.29cvss 5.5epss 0.00

    openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen…

  • CVE-2026-81687MedAug 27, 2026
    risk 0.29cvss 5.5epss 0.00

    openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with extremely high KDF iteration counts to consume CPU resources for unbounded periods before password…

  • CVE-2026-81716MedAug 27, 2026
    risk 0.27cvss 5.2epss 0.00

    openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permission could read or write another plugin's…

  • CVE-2026-74887LowAug 17, 2026
    risk 0.24cvss 3.7epss 0.00

    openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import…

  • CVE-2026-81681MedAug 27, 2026
    risk 0.23cvss 4.6epss 0.00

    openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace directory is actually stored in cleartext and…

  • CVE-2026-74885LowAug 17, 2026
    risk 0.23cvss 3.6epss 0.00

    openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook…

  • CVE-2026-74870LowAug 17, 2026
    risk 0.21cvss 3.3epss 0.00

    openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, handle_hsm_command). The…

  • CVE-2026-81680MedAug 27, 2026
    risk 0.19cvss 4.0epss 0.00

    openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass…

  • CVE-2026-81717LowAug 27, 2026
    risk 0.16cvss 3.5epss 0.00

    openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files…