openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files with excessive memory_cost values that cause the host to crash when unlocking identities before authentication.
References
| Link | Resource |
|---|---|
| https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-783h-8q2f-f762 | Vendor Advisory |
| https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-denial-of-service-via-unbounded-argon2 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-27 17:21
Updated : 2026-09-03 15:09
NVD link : CVE-2026-81720
Mitre link : CVE-2026-81720
CVE.ORG link : CVE-2026-81720
JSON object : View
Products Affected
jahlives
- openssl_encrypt
CWE
CWE-400
Uncontrolled Resource Consumption
