PT-2026-82615 · Unknown · Openssl-Encrypt

CVE-2026-81720

·

Published

2026-08-27

·

Updated

2026-09-03

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description An issue exists where the software fails to validate the memory cost parameter within identity file protection blocks. This allows an attacker with write access to local identity stores to create malicious identity files with excessive memory cost values. When the system attempts to unlock identities before authentication, it can trigger out-of-memory conditions during key derivation, leading to a host crash.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81720
GHSA-783H-8Q2F-F762
PYSEC-2026-3965

Affected Products

Openssl-Encrypt