Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-81693

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 27.1%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-81693


Contact Us

Shodan ® - All rights reserved