PT-2026-82601 · Pypi · Openssl-Encrypt

CVE-2026-81700

·

Published

2026-08-27

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description A signature verification issue exists in the gpg runner.verify detached() function. The system accepts revoked and expired keys because it only checks the VALIDSIG status and fails to inspect REVKEYSIG, EXPKEYSIG, or gpg exit codes. This allows attackers with compromised-then-revoked or expired signing keys to bypass verification and execute malicious plugins within the host process.
Recommendations Update openssl encrypt to version 1.4.9 or later. As a temporary workaround, restrict the use of the gpg runner.verify detached() function until the update is applied.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81700
GHSA-X38R-8WF3-Q9HQ
PYSEC-2026-3777

Affected Products

Openssl-Encrypt