Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-81695: OpenSSL <1.4.9 can display forged terminal messages
CVE-2026-81695 · published 1 month ago
Summary
Versions of OpenSSL prior to 1.4.9 may show attacker‑controlled text on the screen when automatically detecting the encryption key. A crafted encrypted file can cause the program to print misleading information, potentially confusing verification results. Upgrade OpenSSL to version 1.4.9 or later, or apply the vendor’s patch, to stop this behavior.
What to do
- Update jahlives openssl_encrypt to version 1.4.9 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
Original advisory text
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id con...
openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing escape sequences to repaint terminal output and forge authenticity verification blocks.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-jwfm-99h7-2... vendor-advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-terminal-injec... third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-81695 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81695... Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 3.3 (MITRE)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-117Improper Output Neutralization for Logs
Timeline
Published27 Aug 2026
Updated27 Sep 2026
First seen27 Aug 2026
Track software like this
Free during beta