PT-2026-82594 · Unknown · Openssl-Encrypt

CVE-2026-81693

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description The software fails to validate the total field within QR JSON payloads before materializing ranges. An attacker can provide specially crafted QR images containing extremely large values in the total field to trigger unbounded memory allocation, leading to a denial of service due to out-of-memory conditions.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81693
GHSA-R23M-GF2M-8WWW
PYSEC-2026-3798

Affected Products

Openssl-Encrypt