在 1.4.9 之前的版本中,当密码通过捆绑的短选项写法(例如 )或缩写形式的长选项(例如 )提供时,在其 参数转储中无法正确隐藏(redact)文件密码。该消毒器(sanitizer)仅能识别精确的选项名称、 形式以及以 开头的令牌,因此这些写法会绕过密码隐藏的关键控制点,导致明文密码被写入标准错误输出(stderr)。任何能够访问该输出的人(包括终端滚动缓冲区、合并的 输出、CI 作业日志或 GUI 的持久化调试日志)都可能恢复出该密码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
affected |
1.4.9 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jahlives | openssl_encrypt | 0 ~ 1.4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81707 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email |
| CVE-2026-81701 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin |
| CVE-2026-81700 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 GPG Signature Verification Bypass |
| CVE-2026-81702 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Key Substitution via Identity Load |
| CVE-2026-81683 | 8.4 HIGH | openssl_encrypt before 1.4.9 Plaintext Private Key Storage |
| CVE-2026-81719 | 7.8 HIGH | openssl_encrypt before 1.4.9 Remote Code Execution via Plugin |
| CVE-2026-81704 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus |
| CVE-2026-81691 | 7.5 HIGH | openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs |
| CVE-2026-81721 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via KDF |
| CVE-2026-81698 | 7.5 HIGH | openssl_encrypt before 1.4.9 Shell Injection via info command |
| CVE-2026-81693 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via QR total field |
| CVE-2026-81689 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Pepper Key Derivation |
| CVE-2026-81699 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via unbounded KDF cost |
| CVE-2026-81692 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO |
| CVE-2026-81688 | 7.5 HIGH | openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256 |
| CVE-2026-81718 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Cryptographic Parameters |
| CVE-2026-81690 | 7.3 HIGH | verify-usb before 1.4.9 Symlink Directory Traversal Code Execution |
| CVE-2026-81714 | 7.0 HIGH | openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass |
| CVE-2026-81706 | 6.8 MEDIUM | openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing |
| CVE-2026-81686 | 6.2 MEDIUM | openssl_encrypt before 1.4.9 D-Bus Properties Authorization Bypass |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet