VYPR

Openssl Encrypt

by Jahlives

Source repositories

CVEs (64)

  • CVE-2026-81696LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.

  • CVE-2026-81695LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity…

  • CVE-2026-81694LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filenames containing terminal cursor-movement…

  • CVE-2026-81685LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog. Attackers can craft encrypted files with malicious slot…

Page 4 of 4