HIGHVulnerability

CVE-2026-81699

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system resources and crash or wedge the process before password verification occurs.

Properties

severity
HIGH
score
7.5
epss_score
0.00353
cve_id
CVE-2026-81699
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-27T17:21:00.217
last_modified
2026-09-03T15:09:04.887
epss_percentile
0.28367

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81699 — Ninja Signal Threat Intelligence | Ninja Signal