Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

openssl_encrypt — Vulnerabilities & Security Advisories 66

All 66 CVE vulnerabilities found in openssl_encrypt, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for openssl_encrypt, a function within the OpenSSL cryptography library, categorized under the weakness type of Cryptographic Issues. The collection comprises security flaws reported in the openssl_encrypt function and related components, covering disclosures from 2005 to the present year. Readers can utilize this index to track specific advisories issued by the vendor, analyze the prevalence and evolution of cryptographic implementation errors, and review the complete vulnerability history associated with this cryptographic primitive. The data supports security audits and risk assessment by providing a consolidated view of past weaknesses, including improper key handling, predictable random number generation, and insufficient algorithm strength. By examining the timeline and severity scores, organizations can identify recurring patterns in implementation failures and assess the long-term stability of their cryptographic infrastructure. This resource serves as a technical reference for developers and security professionals seeking to understand historical failure points in OpenSSL encryption functions, enabling better-informed decisions regarding library updates, code refactoring, and the adoption of modern cryptographic standards to mitigate known and emerging threats.

Vendor: jahlives

CVE ID Title CVSS Severity Published
CVE-2026-81684 openssl_encrypt before 1.4.9 Information Disclosure via Command Line CWE-214 6.2 Medium 2026-08-27
CVE-2026-81685 openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata CWE-116 3.3 Low 2026-08-27
CVE-2026-81683 openssl_encrypt before 1.4.9 Plaintext Private Key Storage CWE-312 8.4 High 2026-08-27
CVE-2026-81682 openssl_encrypt before 1.4.9 Insecure File Permissions CWE-276 6.2 Medium 2026-08-27
CVE-2026-81681 openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage CWE-311 4.6 Medium 2026-08-27
CVE-2026-81680 openssl_encrypt before 1.4.9 Authentication Bypass via Recovery Slot Removal CWE-347 4.0 Medium 2026-08-27
CVE-2026-74901 openssl_encrypt before 1.4.0 Authentication Bypass via AES-CTR Fallback CWE-347 9.8 Critical 2026-08-17
CVE-2026-74900 openssl_encrypt before 1.4.0 Weak Shared Secret via PQC Simulation Mode CWE-391 9.8 Critical 2026-08-17
CVE-2026-74899 openssl_encrypt before 1.4.0 Sandbox Escape via Type Hierarchy CWE-95 9.8 Critical 2026-08-17
CVE-2026-74896 openssl_encrypt before 1.4.0 Sandbox Escape via Dunder Attribute Traversal CWE-693 9.8 Critical 2026-08-17
CVE-2026-74895 openssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process Isolation CWE-693 9.8 Critical 2026-08-17
CVE-2026-74894 openssl_encrypt before 1.4.0 Authentication Bypass via Bearer Token CWE-287 9.8 Critical 2026-08-17
CVE-2026-74893 openssl_encrypt before 1.4.0 JWT Token Forgery via Hardcoded Secrets CWE-798 8.8 High 2026-08-17
CVE-2026-74891 openssl_encrypt before 1.4.0 Hardcoded Database Credentials CWE-798 9.8 Critical 2026-08-17
CVE-2026-74892 openssl_encrypt before 1.4.0 Hardcoded Secret Key CWE-798 7.5 High 2026-08-17
CVE-2026-74890 openssl_encrypt before 1.4.0 HMAC Authentication Bypass via Environment Variable CWE-345 5.5 Medium 2026-08-17
CVE-2026-74889 openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF CWE-326 9.8 Critical 2026-08-17
CVE-2026-74888 openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation CWE-327 7.5 High 2026-08-17
CVE-2026-74887 openssl_encrypt before 1.4.0 Insecure Random Import in PQC Module CWE-338 3.7 Low 2026-08-17
CVE-2026-74886 openssl_encrypt before 1.4.0 Plugin Import Guard Bypass CWE-184 9.8 Critical 2026-08-17
CVE-2026-74885 openssl_encrypt before 1.4.0 Logging Bug and Race Condition CWE-117 3.6 Low 2026-08-17
CVE-2026-74884 openssl_encrypt before 1.4.0 Path Traversal via plugin_id CWE-73 7.5 High 2026-08-17
CVE-2026-74883 openssl_encrypt before 1.4.0 Sandbox Bypass via pathlib and io CWE-693 8.8 High 2026-08-17
CVE-2026-74882 openssl_encrypt before 1.4.0 Insecure Default Configuration CWE-345 7.5 High 2026-08-17
CVE-2026-74881 openssl_encrypt before 1.4.0 CORS Misconfiguration via Wildcard Origins CWE-942 6.5 Medium 2026-08-17
CVE-2026-74880 openssl_encrypt before 1.4.0 Token Leakage via Query Parameters CWE-598 9.8 Critical 2026-08-17
CVE-2026-74879 openssl_encrypt before 1.4.0 Information Disclosure via /ready endpoint CWE-209 7.5 High 2026-08-17
CVE-2026-74878 openssl_encrypt before 1.4.0 TOTP Rate Limiter Bypass CWE-770 9.8 Critical 2026-08-17
CVE-2026-74877 openssl_encrypt before 1.4.0 Missing Ownership Verification via revoke_key CWE-639 8.8 High 2026-08-17
CVE-2026-74875 openssl_encrypt before 1.4.0 Schema Validation Bypass CWE-345 9.8 Critical 2026-08-17

All 66 known CVE vulnerabilities affecting openssl_encrypt with full Chinese analysis, references, and POCs where available.