Denial of Service in OpenSSL Encrypt Versions by OpenSSL
CVE-2026-81699
8.7HIGH
What is CVE-2026-81699?
The unpatched versions of openssl_encrypt before 1.4.9 are vulnerable to a denial of service attack stemming from improper validation of key derivation function (KDF) costs. Attackers can exploit this vulnerability by supplying maliciously crafted files with excessive KDF parameters, leading to unbounded memory and CPU exhaustion during pre-authentication processing. This can result in resource exhaustion, causing the system to crash or become unresponsive before password verification takes place.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
