CVE-2026-81680

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently removing recovery paths the owner deliberately added.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jahlives:openssl_encrypt:*:*:*:*:*:python:*:*

History

No history.

Information

Published : 2026-08-27 17:20

Updated : 2026-09-03 15:06


NVD link : CVE-2026-81680

Mitre link : CVE-2026-81680

CVE.ORG link : CVE-2026-81680


JSON object : View

Products Affected

jahlives

  • openssl_encrypt
CWE
CWE-347

Improper Verification of Cryptographic Signature