HIGH๐Ÿ‡ต๐Ÿ‡ฑ Wersja polska

CVE-2026-81693

CVSS 8.7v4.0pub. 2026-08-27upd. 2026-09-02

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Jahlives OpenSSL Encrypt

    APP
    Jahlives
    < 1.4.9
๐Ÿ”ต
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2026-81685CRITICAL9.3same product

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing att...

CVE-2026-81694CRITICAL9.3same product

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (o...

CVE-2026-81680CRITICAL9.3same product

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted...

CVE-2026-81681CRITICAL9.3same product

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encr...

CVE-2026-81695CRITICAL9.3same product

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr durin...

CVE-2026-81693 โ€” Jahlives โ€” Openssl Encrypt โ€” HIGH โ€” CVSS 8.7 | CVEbaza.pl