Jahlives Openssl Encrypt — known CVE vulnerabilities
Every CVE whose affected-product data names Jahlives Openssl Encrypt, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (60)
CVE-2026-74891 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the…
CVE-2026-74886 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of…
CVE-2026-74875 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed…
CVE-2026-74889 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy…
CVE-2026-74901 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger…
CVE-2026-74876 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data…
CVE-2026-74894 — CVSS 9.8 (critical): openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty…
CVE-2026-74895 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution…
CVE-2026-74896 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to…
CVE-2026-74899 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in…
CVE-2026-74900 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to…
CVE-2026-74878 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and…
CVE-2026-74872 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses…
CVE-2026-74880 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can…
CVE-2026-81701 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/…
CVE-2026-81702 — CVSS 9.8 (critical): openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to…
CVE-2026-81700 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and…
CVE-2026-74893 — CVSS 8.8 (high): openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers…
CVE-2026-74883 — CVSS 8.8 (high): openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file…
CVE-2026-74877 — CVSS 8.8 (high): openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows…
CVE-2026-81683 — CVSS 8.4 (high): openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a…
CVE-2026-81719 — CVSS 7.8 (high): openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to…
CVE-2026-81699 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to…
CVE-2026-74874 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the…
CVE-2026-74879 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database…
CVE-2026-74882 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in…
CVE-2026-74884 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is…
CVE-2026-74888 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop…
CVE-2026-74892 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used…
CVE-2026-81688 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can…
CVE-2026-81689 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password…
CVE-2026-81691 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted…
CVE-2026-81693 — CVSS 7.5 (high): openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply…
CVE-2026-81698 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that…
CVE-2026-81704 — CVSS 7.5 (high): openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses…
CVE-2026-81705 — CVSS 7.5 (high): openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled…
CVE-2026-81721 — CVSS 7.5 (high): openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to…
CVE-2026-81690 — CVSS 7.3 (high): openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan…
CVE-2026-81714 — CVSS 7.0 (high): openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a…
CVE-2026-81706 — CVSS 6.8 (medium): openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers…
CVE-2026-74881 — CVSS 6.5 (medium): openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers…
CVE-2026-81686 — CVSS 6.2 (medium): openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs…
CVE-2026-81684 — CVSS 6.2 (medium): In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child…
CVE-2026-81720 — CVSS 6.2 (medium): openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to…
CVE-2026-74871 — CVSS 6.2 (medium): openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out…
CVE-2026-74890 — CVSS 5.5 (medium): openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation…
CVE-2026-81703 — CVSS 5.5 (medium): openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers…
CVE-2026-74873 — CVSS 5.5 (medium): openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system…
CVE-2026-81716 — CVSS 5.2 (medium): openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized…
CVE-2026-81681 — CVSS 4.6 (medium): openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with…
CVE-2026-81680 — CVSS 4.0 (medium): openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to…
CVE-2026-74887 — CVSS 3.7 (low): openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of…
CVE-2026-74885 — CVSS 3.6 (low): openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always…
CVE-2026-81717 — CVSS 3.5 (low): openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model…
CVE-2026-74870 — CVSS 3.3 (low): openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test'…
CVE-2026-81696 — CVSS 3.3 (low): openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers…
CVE-2026-81685 — CVSS 3.3 (low): openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control…
CVE-2026-81694 — CVSS 3.3 (low): openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM…
CVE-2026-81715 — CVSS 3.3 (low): openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument…
CVE-2026-81695 — CVSS 3.3 (low): openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection…