← Terug naar overzicht

A denial-of-service vulnerability exists in openssl_encrypt versions before 1.4.9. The library fails to validate the 'total' field from QR JSON payloads prior to materializing ranges, allowing attackers to craft malicious QR images containing extremely large total values. This triggers unbounded memory allocation, leading to out-of-memory conditions and denial of service. No authentication or special privileges appear to be required to exploit this vulnerability, as attackers only need to supply a crafted QR image. A fix is available in version 1.4.9 of the openssl_encrypt library. The vulnerability has been assigned CVE-2026-81693 and is documented on NVD as well as GitHub Security Advisories and VulnCheck.

Affected products

  • openssl_encrypt before 1.4.9

Related CVE's

  • CVE-2026-81693

Categories

  • Supply Chain & Dependencies
  • Web Technologies