Denial of Service Vulnerability in OpenSSL Encrypt Product by OpenSSL
CVE-2026-81720
6.9MEDIUM
What is CVE-2026-81720?
The OpenSSL Encrypt product prior to version 1.4.9 contains a vulnerability that fails to properly validate the memory_cost parameter in identity file protection blocks. This flaw enables attackers with write access to local identity stores to craft malicious identity files containing excessively high memory_cost values. Consequently, when an affected system attempts to unlock these identities before authentication, it may experience out-of-memory conditions, resulting in crashes and disrupting service availability.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
