openssl-encrypt
PyPI60 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openssl-encryptpage 2 of 2
- CVE-2026-81704HIGHCVSS 7.5EG 7.5✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against enc…
- CVE-2026-81705HIGHCVSS 7.5EG 7.5✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. --passw). The sanitizer o…
- CVE-2026-81706MEDIUMCVSS 6.8EG 6.8✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When …
- CVE-2026-81714HIGHCVSS 7.0EG 7.0✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG key id could unknow…
- CVE-2026-81715LOWCVSS 3.3EG 3.3✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to sanitize…
- CVE-2026-81716MEDIUMCVSS 5.2EG 5.2✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permission …
- CVE-2026-81717LOWCVSS 3.5EG 3.5✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify…
- CVE-2026-81719HIGHCVSS 7.8EG 7.8✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at…
- CVE-2026-81720MEDIUMCVSS 6.2EG 6.2✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stor…
- CVE-2026-81721HIGHCVSS 7.5EG 7.5✓ Fixed in 1.4.92026-08-27
vulnerable: 0.2.2 ... 1.4.8 (53 versions)
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrar…
Check whether openssl-encrypt is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openssl-encrypt CVEs against the assets you own.
Start Free Scan →