PT-2026-82601 · Pypi · Openssl-Encrypt
CVE-2026-81700
·
Published
2026-08-27
·
Updated
2026-09-01
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openssl encrypt versions prior to 1.4.9
Description
A signature verification issue exists in the
gpg runner.verify detached() function. The system accepts revoked and expired keys because it only checks the VALIDSIG status and fails to inspect REVKEYSIG, EXPKEYSIG, or gpg exit codes. This allows attackers with compromised-then-revoked or expired signing keys to bypass verification and execute malicious plugins within the host process.Recommendations
Update openssl encrypt to version 1.4.9 or later.
As a temporary workaround, restrict the use of the
gpg runner.verify detached() function until the update is applied.Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl-Encrypt