LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-81721

jahlives · openssl encrypt

Published
CVSS7.5
Severityhigh
WeaknessCWE-400
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large Argon2, scrypt, or balloon KDF parameters to exhaust system memory and crash the process without authentication.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-81721

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-81721.