← Terug naar overzicht

A vulnerability in openssl_encrypt before version 1.4.9 allows attackers to inject ANSI escape sequences via unsanitized email fields in imported identity documents. This enables manipulation of terminal output to display fraudulent cryptographic fingerprints, effectively bypassing the out-of-band verification mechanism designed to protect against key substitution attacks. Attackers can deliver crafted identity bundles through standard contact-exchange flows or keyserver responses, making the attack vector accessible and realistic. The core risk is that users performing fingerprint verification — a critical trust step in encrypted communications — can be deceived into accepting a forged key. This undermines the fundamental security model of tools relying on openssl_encrypt for identity verification and key authentication.

Affected products

  • openssl_encrypt

Related CVE's

  • CVE-2026-81707

Categories

  • Identity & Access
  • Security Tools
  • Web Technologies