PT-2026-82616 · Unknown · Openssl-Encrypt

CVE-2026-81721

·

Published

2026-08-27

·

Updated

2026-08-31

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openssl encrypt versions prior to 1.4.9
Description The software fails to validate Key Derivation Function (KDF) cost parameters within encrypted file metadata and keystore headers. This allows an unauthenticated attacker to trigger unbounded memory allocation by crafting malicious encrypted files that declare arbitrarily large parameters for Argon2, scrypt, or balloon KDFs, leading to system memory exhaustion and process crashes.
Recommendations Update to version 1.4.9 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81721
GHSA-7894-5GW8-69HR
PYSEC-2026-3803

Affected Products

Openssl-Encrypt