← Back to overview

A denial-of-service vulnerability exists in openssl_encrypt versions prior to 1.4.9. The software fails to validate Key Derivation Function (KDF) cost parameters found in encrypted file metadata and keystore headers. Attackers can craft malicious encrypted files with arbitrarily large Argon2, scrypt, or balloon KDF parameters to trigger unbounded memory allocation. This leads to memory exhaustion and process crashes. No authentication is required to exploit this vulnerability. The flaw affects any system processing attacker-controlled encrypted files using the vulnerable library. A fix is available in version 1.4.9 and later. The issue is tracked as CVE-2026-81721 and has been assigned a high severity rating.

Affected products

  • openssl_encrypt before 1.4.9

Related CVE's

  • CVE-2026-81721

Categories

  • Security Tools
  • Supply Chain & Dependencies