Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-81707: openssl_encrypt <1.4.9 can fake fingerprint display
CVE-2026-81707 · published 7 days ago
Summary
Versions of the OpenSSL encryption library older than 1.4.9 that process identity documents may let a malicious email insert special control codes. Those codes can change what your terminal shows, making a fake fingerprint appear and allowing an attacker to replace a trusted key without you noticing. Update to version 1.4.9 or later (or apply the provided patch) and verify keys using another trusted method.
What to do
- Update jahlives openssl_encrypt to version 1.4.9 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
Original advisory text
openssl_encrypt before 1.4.9 ANSI Escape Injection via Identity Email
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing the out-of-band verification mechanism that protects against key substitution attacks.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-qjr2-x6mr-8...
- https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-ansi-escape-in...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81707... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-81707 Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-20Improper Input Validation
Timeline
Published27 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Monitor software like this
Free during beta