PT-2026-82600 · Unknown · Openssl-Encrypt

CVE-2026-81699

·

Published

2026-08-27

·

Updated

2026-09-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description Insufficient validation of key derivation function (KDF) costs in crafted files allows attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. By supplying malicious files with excessive KDF parameters, an attacker can exhaust system resources, leading to a process crash or hang before password verification takes place.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81699
GHSA-PHMR-P567-Q5G6
PYSEC-2026-3961

Affected Products

Openssl-Encrypt