CRITICAL 9.3 NVD
CVE-2026-81707
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing the out-of-band verification mechanism that protects against key substitution attacks.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-qjr2-x6mr-8xgf
- https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-ansi-escape-injection-vi
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-27 via NVD.
Risk Timeline
CVE Disclosed2026-08-27 · -1 days ago
Remediation Resources
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.