Jahlives Openssl Encrypt

36 known vulnerabilities in Jahlives Openssl Encrypt, 15 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-81721 CVSS 8.7 high openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to…
  • CVE-2026-81720 CVSS 6.9 medium openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to…
  • CVE-2026-81719 CVSS 9.3 critical openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to…
  • CVE-2026-81718 CVSS 8.7 high openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile…
  • CVE-2026-81717 CVSS 9.3 critical openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model…
  • CVE-2026-81716 CVSS 8.7 high openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which…
  • CVE-2026-81715 CVSS 8.7 high openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument…
  • CVE-2026-81714 CVSS 9.3 critical openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a…
  • CVE-2026-81707 CVSS 9.3 critical openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape…
  • CVE-2026-81706 CVSS 9.3 critical openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing…
  • CVE-2026-81705 CVSS 8.7 high openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled…
  • CVE-2026-81704 CVSS 8.7 high openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses…
  • CVE-2026-81703 CVSS 8.7 high openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers…
  • CVE-2026-81702 CVSS 9.3 critical openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers…
  • CVE-2026-81701 CVSS 9.3 critical openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/…
  • CVE-2026-81700 CVSS 9.3 critical openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked…
  • CVE-2026-81699 CVSS 8.7 high openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to…
  • CVE-2026-81698 CVSS 9.3 critical openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that…
  • CVE-2026-81697 CVSS 8.7 high openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in…
  • CVE-2026-81696 CVSS 9.3 critical openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers…
  • CVE-2026-81695 CVSS 9.3 critical openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection…
  • CVE-2026-81694 CVSS 9.3 critical openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM…
  • CVE-2026-81693 CVSS 8.7 high openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply…
  • CVE-2026-81692 CVSS 8.7 high openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files…
  • CVE-2026-81691 CVSS 8.7 high openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted…
  • CVE-2026-81690 CVSS 8.7 high openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan…
  • CVE-2026-81689 CVSS 8.7 high openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password…
  • CVE-2026-81688 CVSS 8.7 high openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can…
  • CVE-2026-81687 CVSS 8.7 high openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file…
  • CVE-2026-81686 CVSS 6.9 medium openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs…