CRITICAL 9.3 NVD
CVE-2026-81696
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious f
openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repaint terminal output and forge verification information displayed to users.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-539p-fxf4-7fv8
- https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-terminal-injection-via-i
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-27 via NVD.
Risk Timeline
CVE Disclosed2026-08-27 · -1 days ago
Remediation Resources
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.