← Back to overview

openssl_encrypt versions before 1.4.9 contain a vulnerability in the login and register_with_email functions that fail to validate server URLs, allowing unencrypted http:// URLs and unconfigured hosts. This exposes sensitive credentials including client_id, passwords, and JWTs in cleartext over the network. Attackers positioned on the network path can intercept these credentials through a man-in-the-middle style attack. Successful exploitation can lead to full keyserver account takeover. The vulnerability has been assigned CVE-2026-81691 and is rated high severity. Users should upgrade to version 1.4.9 or later to remediate the issue.

Affected products

  • openssl_encrypt (versions before 1.4.9)

Related CVE's

  • CVE-2026-81691

Categories

  • Identity & Access
  • Security Tools
  • Web Technologies