(PyPI 包名: )版本 ≤ 1.4.8 存在一个漏洞:当使用 参数时,调试输出(argv 转储)中未对以位置参数形式传递给 的密钥服务器 Bearer Token 进行脱敏,因为 函数未能对其进行清理。这导致该 Token 在 模式下(即使未启用 )以明文形式打印到标准错误输出(stderr),从而使凭据被保留在日志和终端历史记录中。该问题已在 1.4.9 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
affected |
1.4.9 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jahlives | openssl_encrypt | 0 ~ 1.4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81707 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email |
| CVE-2026-81702 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Key Substitution via Identity Load |
| CVE-2026-81700 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 GPG Signature Verification Bypass |
| CVE-2026-81701 | 9.8 CRITICAL | openssl_encrypt before 1.4.9 Arbitrary Code Execution via unsigned plugin |
| CVE-2026-81683 | 8.4 HIGH | openssl_encrypt before 1.4.9 Plaintext Private Key Storage |
| CVE-2026-81719 | 7.8 HIGH | openssl_encrypt before 1.4.9 Remote Code Execution via Plugin |
| CVE-2026-81718 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Cryptographic Parameters |
| CVE-2026-81704 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus |
| CVE-2026-81691 | 7.5 HIGH | openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs |
| CVE-2026-81721 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via KDF |
| CVE-2026-81698 | 7.5 HIGH | openssl_encrypt before 1.4.9 Shell Injection via info command |
| CVE-2026-81693 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via QR total field |
| CVE-2026-81688 | 7.5 HIGH | openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256 |
| CVE-2026-81705 | 7.5 HIGH | openssl-encrypt before 1.4.9 Password Cleartext Leak via Debug |
| CVE-2026-81689 | 7.5 HIGH | openssl_encrypt before 1.4.9 Weak Pepper Key Derivation |
| CVE-2026-81699 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via unbounded KDF cost |
| CVE-2026-81692 | 7.5 HIGH | openssl_encrypt before 1.4.9 Denial of Service via STREAMINFO |
| CVE-2026-81690 | 7.3 HIGH | verify-usb before 1.4.9 Symlink Directory Traversal Code Execution |
| CVE-2026-81714 | 7.0 HIGH | openssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment Bypass |
| CVE-2026-81706 | 6.8 MEDIUM | openssl_encrypt before 1.4.9 Key Substitution via Identity Shadowing |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet