Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-81720

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files with excessive memory_cost values that cause the host to crash when unlocking identities before authentication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 2.6%
CVSS Severity
CVSS v3 Score 6.2
Products affected by CVE-2026-81720


Contact Us

Shodan ® - All rights reserved