Denial of Service Risk in OpenSSL Encryption Tool by OpenSSL
CVE-2026-81721
8.7HIGH
What is CVE-2026-81721?
The OpenSSL encryption tool, specifically the openssl_encrypt component prior to version 1.4.9, is susceptible to a Denial of Service vulnerability due to improper validation of Key Derivation Function (KDF) cost parameters in encrypted file metadata and keystore headers. Attackers can exploit this flaw by crafting malicious encrypted files that declare excessively large Argon2, scrypt, or balloon KDF parameters. This design oversight allows for unbounded memory allocation, potentially leading to system memory exhaustion and process crashes without the need for authentication. As such, it poses a significant risk to the stability and availability of affected systems.
Affected Version(s)
openssl_encrypt 0 < 1.4.9
openssl_encrypt 1.4.9
