Loading market data...
← Back to CVE feed

CVE-2026-81720

MEDIUM CVSS 6.2 View on NVD ↗

Description

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files with excessive memory_cost values that cause the host to crash when unlocking identities before authentication.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: Aug 27, 2026 17:21 UTC Modified: Aug 27, 2026 17:21 UTC