以下是该漏洞描述的中文翻译: openssl_encrypt(PyPI 包名:openssl-encrypt) 在 1.4.8 及更早版本中,通过桌面端图形界面(GUI)的“设置”屏幕中“合并证书与私钥”PEM 字段,将 mTLS 客户端私钥以明文形式存储在权限为 0644(所有用户可读)的 SharedPreferences 文件中。拥有文件系统访问权限的本地攻击者可以读取该暴露的私钥。 1.4.9 版本将 PEM 内容写入一个专用且权限为 0600(仅所有者可读写)的文件,仅在 SharedPreference
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
affected |
1.4.9 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jahlives | openssl_encrypt | 0 ~ 1.4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81707 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email |
| CVE-2026-81701 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin |
| CVE-2026-81700 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 GPG Signature Verification Bypass |
| CVE-2026-81702 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Key Substitution via Identity Load |
| CVE-2026-81719 | 7.8 HIGH | openssl_encrypt before 1.4.9 Remote Code Execution via Plugin |
| CVE-2026-81721 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via KDF |
| CVE-2026-81698 | 7.5 HIGH | openssl_encrypt before 1.4.9 Shell Injection via info command |
| CVE-2026-81704 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus |
| CVE-2026-81693 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via QR total field |
| CVE-2026-81691 | 7.5 HIGH | openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs |
| CVE-2026-81705 | 7.5 HIGH | openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug |
| CVE-2026-81689 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Pepper Key Derivation |
| CVE-2026-81699 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via unbounded KDF cost |
| CVE-2026-81692 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO |
| CVE-2026-81688 | 7.5 HIGH | openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256 |
| CVE-2026-81718 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Cryptographic Parameters |
| CVE-2026-81690 | 7.3 HIGH | verify-usb before 1.4.9 Symlink Directory Traversal Code Execution |
| CVE-2026-81714 | 7.0 HIGH | openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass |
| CVE-2026-81706 | 6.8 MEDIUM | openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing |
| CVE-2026-81684 | 6.2 MEDIUM | openssl_encrypt before 1.4.9 Information Disclosure via Command Line |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet