Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-81695: OpenSSL <1.4.9 can display forged terminal messages

CVE-2026-81695 · published 1 month ago
Summary

Versions of OpenSSL prior to 1.4.9 may show attacker‑controlled text on the screen when automatically detecting the encryption key. A crafted encrypted file can cause the program to print misleading information, potentially confusing verification results. Upgrade OpenSSL to version 1.4.9 or later, or apply the vendor’s patch, to stop this behavior.

What to do
  • Update jahlives openssl_encrypt to version 1.4.9 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.9
Original advisory text
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id con...
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity verification blocks.
Severity
9.3 Critical
CVSS 3.1: 3.3 (MITRE)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-117Improper Output Neutralization for Logs
Timeline
Published27 Aug 2026
Updated27 Sep 2026
First seen27 Aug 2026
Sources
CVE-2026-81695 · MITRE
Track software like this
Free during beta