← Back to overview

CVE-2026-81699 affects openssl_encrypt versions before 1.4.9, which fail to properly validate key derivation function (KDF) costs in crafted files. Attackers can supply malicious files containing excessive KDF parameters to trigger unbounded memory and CPU exhaustion. The vulnerability is exploitable during pre-authentication processing, meaning no valid credentials are required to launch the attack. Successful exploitation can cause the affected process to crash or become unresponsive. This represents a Denial of Service (DoS) risk that can be triggered remotely before any password verification occurs. The fix is available in openssl_encrypt version 1.4.9 and later.

Affected products

  • openssl_encrypt

Related CVE's

  • CVE-2026-81699

Categories

  • Security Tools
  • Web Technologies