VYPR

openssl_encrypt

by OpenSSL Project

Source repositories

CVEs (6)

  • CVE-2026-81683HigAug 27, 2026
    risk 0.48cvss 8.4epss 0.00

    openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker…

  • CVE-2026-81692HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation (np.random.randint(size=(total_samples, channels))). A ~50-byte crafted FLAC file declaring ~100…

  • CVE-2026-81684MedAug 27, 2026
    risk 0.33cvss 6.2epss 0.00

    In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and decrypt paths) instead of via an environment variable as done…

  • CVE-2026-81697MedAug 27, 2026
    risk 0.29cvss 5.5epss 0.00

    openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is reassigned at line 84 to the bare relative name…

  • CVE-2026-81717LowAug 27, 2026
    risk 0.16cvss 3.5epss 0.00

    openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files…

  • CVE-2026-81696LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.