在 openssl-encrypt(pip 包 openssl-encrypt)版本 1.4.8 及更早版本中,桌面 GUI 在加密和解密流程中,均通过命令行参数 将隐写(steganography)密码传递给 CLI 子进程,而非像主密码那样通过环境变量传递。在该子进程运行期间,任何本地用户都可以通过读取 获取到隐写密码。该问题已在版本 1.4.9 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
affected |
1.4.9 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jahlives | openssl_encrypt | 0 ~ 1.4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81707 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email |
| CVE-2026-81702 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Key Substitution via Identity Load |
| CVE-2026-81701 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin |
| CVE-2026-81700 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 GPG Signature Verification Bypass |
| CVE-2026-81683 | 8.4 HIGH | openssl_encrypt before 1.4.9 Plaintext Private Key Storage |
| CVE-2026-81719 | 7.8 HIGH | openssl_encrypt before 1.4.9 Remote Code Execution via Plugin |
| CVE-2026-81688 | 7.5 HIGH | openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256 |
| CVE-2026-81692 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO |
| CVE-2026-81699 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via unbounded KDF cost |
| CVE-2026-81689 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Pepper Key Derivation |
| CVE-2026-81705 | 7.5 HIGH | openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug |
| CVE-2026-81718 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Cryptographic Parameters |
| CVE-2026-81691 | 7.5 HIGH | openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs |
| CVE-2026-81693 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via QR total field |
| CVE-2026-81698 | 7.5 HIGH | openssl_encrypt before 1.4.9 Shell Injection via info command |
| CVE-2026-81721 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via KDF |
| CVE-2026-81704 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus |
| CVE-2026-81690 | 7.3 HIGH | verify-usb before 1.4.9 Symlink Directory Traversal Code Execution |
| CVE-2026-81714 | 7.0 HIGH | openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass |
| CVE-2026-81706 | 6.8 MEDIUM | openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet