Impact
The vulnerability exists in openssl_encrypt versions prior to 1.4.9, where key derivation function (KDF) costs are not properly validated. An attacker can supply a malicious file containing excessively large KDF parameters, causing the library to consume unbounded amounts of memory and CPU during pre‑authentication processing. This can lead to application crashes or hangs, resulting in a denial of service before any user authentication is performed. The weakness is a resource‑exhaustion flaw identified as CWE-770.
Affected Systems
The product affected is openssl_encrypt from vendor jahlives. All releases older than version 1.4.9 are vulnerable; no further sub‑version enumeration is provided.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity condition. The EPSS score is not available, but the flaw remains likely to be exploited due to the lack of mitigations. The vulnerability is listed as not included in the CISA KEV catalog. Attackers who can supply the crafted file to the openssl_encrypt component—either locally or via an exposed interface—can trigger non‑authentication resource exhaustion. The no‑authentication pre‑processing detail makes the attack vector relatively easy for remote or local adversaries capable of delivering files.
OpenCVE Enrichment