Jahlives
Jahlives Openssl Encrypt: vulnerabilidades y CVE
Jahlives Openssl Encrypt tiene 64 vulnerabilidades publicadas, 64 de ellas en los últimos 12 meses. 30 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE64
Últimos 12 meses64
Críticas30
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81721 | Alta (8.7) | 0.58% | — | 27 ago 2026 | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted… |
| CVE-2026-81720 | Media (6.9) | 0.18% | — | 27 ago 2026 | openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to… |
| CVE-2026-81719 | Crítica (9.3) | 0.44% | — | 27 ago 2026 | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in… |
| CVE-2026-81717 | Crítica (9.3) | 0.12% | — | 27 ago 2026 | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access).… |
| CVE-2026-81716 | Alta (8.7) | 0.26% | — | 27 ago 2026 | openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the… |
| CVE-2026-81715 | Alta (8.7) | 0.26% | — | 27 ago 2026 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because… |
| CVE-2026-81714 | Crítica (9.3) | 0.20% | — | 27 ago 2026 | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG… |
| CVE-2026-81706 | Crítica (9.3) | 0.18% | — | 27 ago 2026 | openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own… |
| CVE-2026-81705 | Alta (8.7) | 0.44% | — | 27 ago 2026 | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g.… |
| CVE-2026-81704 | Alta (8.7) | 0.27% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password… |
| CVE-2026-81703 | Alta (8.7) | 0.22% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any… |
| CVE-2026-81702 | Crítica (9.3) | 0.19% | — | 27 ago 2026 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate… |
| CVE-2026-81701 | Crítica (9.3) | 0.43% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification.… |
| CVE-2026-81700 | Crítica (9.3) | 0.35% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG,… |
| CVE-2026-81699 | Alta (8.7) | 0.51% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing.… |
| CVE-2026-81698 | Crítica (9.3) | 0.43% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata… |
| CVE-2026-81696 | Crítica (9.3) | 0.25% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output… |
| CVE-2026-81695 | Crítica (9.3) | 0.25% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape… |
| CVE-2026-81694 | Crítica (9.3) | 0.25% | — | 27 ago 2026 | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the verify-usb command's output. An… |
| CVE-2026-81693 | Alta (8.7) | 0.49% | — | 27 ago 2026 | openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory… |
| CVE-2026-81691 | Alta (8.7) | 0.27% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept… |
| CVE-2026-81690 | Alta (8.7) | 0.71% | — | 27 ago 2026 | openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked… |
| CVE-2026-81689 | Alta (8.7) | 0.27% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped… |
| CVE-2026-81688 | Alta (8.7) | 0.27% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or… |
| CVE-2026-81686 | Media (6.9) | 0.14% | — | 27 ago 2026 | openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user on the… |
| CVE-2026-81685 | Crítica (9.3) | 0.25% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog.… |
| CVE-2026-81684 | Media (6.9) | 0.17% | — | 27 ago 2026 | In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and… |
| CVE-2026-81683 | Alta (8.6) | 0.07% | — | 27 ago 2026 | openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen… |
| CVE-2026-81681 | Crítica (9.3) | 0.17% | — | 27 ago 2026 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but… |
| CVE-2026-81680 | Crítica (9.3) | 0.20% | — | 27 ago 2026 | openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.