HIGHVulnerability
CVE-2026-81693
openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions.
Properties
- severity
- HIGH
- score
- 7.5
- epss_score
- 0.00343
- cve_id
- CVE-2026-81693
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- published_at
- 2026-08-27T17:20:59.297
- last_modified
- 2026-09-02T13:09:58.050
- epss_percentile
- 0.2727
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Memory Allocation with Excessive Size Value
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (1)
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph