Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81719 | HIGH | 7.8 | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and … | Aug 27, 2026 |
| CVE-2026-81718 | HIGH | 7.5 | openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers … | Aug 27, 2026 |
| CVE-2026-81717 | LOW | 3.5 | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker … | Aug 27, 2026 |
| CVE-2026-81716 | MEDIUM | 5.2 | openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin … | Aug 27, 2026 |
| CVE-2026-81715 | LOW | 3.3 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug … | Aug 27, 2026 |
| CVE-2026-81714 | HIGH | 7.0 | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, … | Aug 27, 2026 |
| CVE-2026-81707 | CRITICAL | 9.8 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification … | Aug 27, 2026 |
| CVE-2026-81706 | MEDIUM | 6.8 | openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the … | Aug 27, 2026 |
| CVE-2026-81705 | HIGH | 7.5 | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) … | Aug 27, 2026 |
| CVE-2026-81704 | HIGH | 7.5 | openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform … | Aug 27, 2026 |
| CVE-2026-81703 | MEDIUM | 5.5 | openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC … | Aug 27, 2026 |
| CVE-2026-81702 | CRITICAL | 9.8 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can … | Aug 27, 2026 |
| CVE-2026-81701 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature … | Aug 27, 2026 |
| CVE-2026-81700 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, … | Aug 27, 2026 |
| CVE-2026-81699 | HIGH | 7.5 | openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during … | Aug 27, 2026 |
| CVE-2026-81698 | HIGH | 7.5 | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can … | Aug 27, 2026 |
| CVE-2026-81697 | MEDIUM | 5.5 | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is … | Aug 27, 2026 |
| CVE-2026-81696 | LOW | 3.3 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape … | Aug 27, 2026 |
| CVE-2026-81695 | LOW | 3.3 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing … | Aug 27, 2026 |
| CVE-2026-81694 | LOW | 3.3 | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the … | Aug 27, 2026 |
| CVE-2026-81693 | HIGH | 7.5 | openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large … | Aug 27, 2026 |
| CVE-2026-81692 | HIGH | 7.5 | openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation … | Aug 27, 2026 |
| CVE-2026-81691 | HIGH | 7.5 | openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network … | Aug 27, 2026 |
| CVE-2026-81690 | HIGH | 7.3 | openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in … | Aug 27, 2026 |
| CVE-2026-81689 | HIGH | 7.5 | openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and … | Aug 27, 2026 |