HIGHVulnerability

CVE-2026-81693

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions.

Properties

severity
HIGH
score
7.5
epss_score
0.00343
cve_id
CVE-2026-81693
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-27T17:20:59.297
last_modified
2026-09-02T13:09:58.050
epss_percentile
0.2727

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Memory Allocation with Excessive Size Value

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81693 — Ninja Signal Threat Intelligence | Ninja Signal