Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-81702

Опубликовано: 27 авг. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jahlives:openssl_encrypt:*:*:*:*:*:python:*:*
Версия до 1.4.9 (исключая)

EPSS

Процентиль: 4%
0.00139
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 9.8
github
26 дней назад

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

EPSS

Процентиль: 4%
0.00139
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-345