Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
465 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.49% | — | Openssl-encryptAI | 27/8/2026 | 23/9/2026 | openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation (np.random.randint(size=(total_samples, channels))). A ~50-byte crafted FLAC file declaring ~100 million samples causes a multi-gigabyte… | |
| Aplazada | Alta (8.7) | 0.29% | — | Jahlives Openssl EncryptAI | 27/8/2026 | 23/9/2026 | openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with extremely high KDF iteration counts to consume CPU resources for unbounded periods before password verification occurs. | |
| Aplazada | Alta (8.6) | 0.16% | — | Jahlives Openssl EncryptAI | 27/8/2026 | 23/9/2026 | openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on multi-user systems. | |
| Analizada | Crítica (9.1) | 0.23% | — | Openssl | 25/8/2026 | 11/9/2026 | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to… | |
| Analizada | Alta (7.5) | 1.6% | — | Openssl | 25/8/2026 | 11/9/2026 | Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer. Impact summary: A… | |
| Analizada | Alta (7.5) | 0.78% | — | Openssl | 25/8/2026 | 11/9/2026 | Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can complete a QUIC handshake can cause… | |
| Analizada | Media (5.9) | 0.59% | — | Openssl | 25/8/2026 | 11/9/2026 | Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood… | |
| Analizada | Crítica (9.8) | 1.2% | — | Openssl | 25/8/2026 | 11/9/2026 | Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject… | |
| Analizada | Alta (7.5) | 0.92% | — | Openssl | 25/8/2026 | 11/9/2026 | Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message… | |
| Analizada | Alta (7.5) | 0.62% | — | Openssl | 25/8/2026 | 11/9/2026 | Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory,… | |
| Analizada | Alta (7.5) | 1.0% | — | Openssl | 25/8/2026 | 11/9/2026 | Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted… | |
| Analizada | Alta (7.5) | 1.5% | — | Openssl | 25/8/2026 | 23/9/2026 | Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double… | |
| Aplazada | Media (5.3) | 0.24% | — | OpensslAITypo3AI | 25/8/2026 | 26/8/2026 | When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key. | |
| Aplazada | Alta (7.4) | 0.37% | — | OpensslAIJoinmastodon MastodonAI | 18/8/2026 | 16/9/2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate… | |
| Analizada | Crítica (9.3) | 0.40% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection. | |
| Analizada | Crítica (9.3) | 0.56% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 16 bytes of the… | |
| Analizada | Crítica (9.3) | 0.75% | — | Jahlives Openssl Encrypt | 17/8/2026 | 28/8/2026 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands. | |
| Analizada | Crítica (9.3) | 0.56% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary… | |
| Analizada | Crítica (9.3) | 0.68% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules. | |
| Analizada | Crítica (9.3) | 0.66% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the… | |
| Analizada | Alta (8.7) | 0.45% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs. | |
| Analizada | Alta (8.7) | 0.51% | — | Jahlives Openssl Encrypt | 17/8/2026 | 31/8/2026 | openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication. | |
| Analizada | Alta (8.7) | 0.52% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data. | |
| Analizada | Crítica (9.3) | 0.21% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticated ciphertext and… | |
| Analizada | Crítica (9.3) | 0.35% | — | Jahlives Openssl Encrypt | 17/8/2026 | 1/9/2026 | openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks. |