Description
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover. | |
| Title | openssl_encrypt before 1.4.9 Credential Leakage via Unvalidated Server URLs | |
| Weaknesses | CWE-319 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T14:50:56.151Z
Reserved: 2026-08-27T11:12:00.889Z
Link: CVE-2026-81691
No data.
Status : Received
Published: 2026-08-27T17:20:58.993
Modified: 2026-08-27T17:20:58.993
Link: CVE-2026-81691
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-319
Cleartext Transmission of Sensitive Information