以下是对该漏洞描述的中文翻译: **OpenSSL 1.4.9 之前的 功能未能对导入的身份文档(identity document)中的 email 字段进行净化(sanitize),允许攻击者通过注入 ANSI 转义序列来伪造向用户显示的指纹验证行。攻击者可以通过正常的联系人交换流程或密钥服务器(keyserver)响应,投递一个经过构造的身份数据束(identity bundle),从而操纵终端输出并显示一个虚假的指纹,进而绕过保护用户免受密钥替换攻击的带外(out-of-band)验证机制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
affected |
1.4.9 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jahlives | openssl_encrypt | 0 ~ 1.4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81701 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin |
| CVE-2026-81700 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 GPG Signature Verification Bypass |
| CVE-2026-81702 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Key Substitution via Identity Load |
| CVE-2026-81683 | 8.4 HIGH | openssl_encrypt before 1.4.9 Plaintext Private Key Storage |
| CVE-2026-81719 | 7.8 HIGH | openssl_encrypt before 1.4.9 Remote Code Execution via Plugin |
| CVE-2026-81689 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Pepper Key Derivation |
| CVE-2026-81704 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus |
| CVE-2026-81721 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via KDF |
| CVE-2026-81691 | 7.5 HIGH | openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs |
| CVE-2026-81693 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via QR total field |
| CVE-2026-81705 | 7.5 HIGH | openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug |
| CVE-2026-81699 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via unbounded KDF cost |
| CVE-2026-81692 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO |
| CVE-2026-81688 | 7.5 HIGH | openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256 |
| CVE-2026-81718 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Cryptographic Parameters |
| CVE-2026-81698 | 7.5 HIGH | openssl_encrypt before 1.4.9 Shell Injection via info command |
| CVE-2026-81690 | 7.3 HIGH | verify-usb before 1.4.9 Symlink Directory Traversal Code Execution |
| CVE-2026-81714 | 7.0 HIGH | openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass |
| CVE-2026-81706 | 6.8 MEDIUM | openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing |
| CVE-2026-81720 | 6.2 MEDIUM | openssl_encrypt before 1.4.9 Denial of Service via Unbounded Argon2 |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet