CVE-2026-81693

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jahlives:openssl_encrypt:*:*:*:*:*:python:*:*

History

No history.

Information

Published : 2026-08-27 17:20

Updated : 2026-09-02 13:09


NVD link : CVE-2026-81693

Mitre link : CVE-2026-81693

CVE.ORG link : CVE-2026-81693


JSON object : View

Products Affected

jahlives

  • openssl_encrypt
CWE
CWE-789

Memory Allocation with Excessive Size Value