VYPR

Vendor CVEs

Jahlives

All CVEs

65 total · sorted by risk
  • CVE-2026-81682MedAug 27, 2026
    risk 0.33cvss 6.2epss 0.00

    openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on…

  • CVE-2026-81703MedAug 27, 2026
    risk 0.29cvss 5.5epss 0.00

    openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen…

  • CVE-2026-81687MedAug 27, 2026
    risk 0.29cvss 5.5epss 0.00

    openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with extremely high KDF iteration counts to consume CPU resources for unbounded periods before password…

  • CVE-2026-81716MedAug 27, 2026
    risk 0.27cvss 5.2epss 0.00

    openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permission could read or write another plugin's…

  • CVE-2026-74887LowAug 17, 2026
    risk 0.24cvss 3.7epss 0.00

    openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the code, so no cryptographic operation is currently affected; however, the import…

  • CVE-2026-81681MedAug 27, 2026
    risk 0.23cvss 4.6epss 0.00

    openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace directory is actually stored in cleartext and…

  • CVE-2026-74885LowAug 17, 2026
    risk 0.23cvss 3.6epss 0.00

    openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook…

  • CVE-2026-74870LowAug 17, 2026
    risk 0.21cvss 3.3epss 0.00

    openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, handle_hsm_command). The…

  • CVE-2026-81680MedAug 27, 2026
    risk 0.19cvss 4.0epss 0.00

    openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass…

  • CVE-2026-81717LowAug 27, 2026
    risk 0.16cvss 3.5epss 0.00

    openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files…

  • CVE-2026-81715LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to sanitize it. As a result the token is printed in…

  • CVE-2026-81696LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.

  • CVE-2026-81695LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity…

  • CVE-2026-81694LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An attacker can plant filenames containing terminal cursor-movement…

  • CVE-2026-81685LowAug 27, 2026
    risk 0.14cvss 3.3epss 0.00

    openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog. Attackers can craft encrypted files with malicious slot…

Page 2 of 2