Junglewise Threat Intelligence

CVE-2026-81680: openssl_encrypt recovery-slot authentication bypass

CVE-2026-81680 · Severity: medium · CVSS 4 · Published 2026-08-27

Technologies: openssl-encrypt (PyPI), Jahlives Openssl Encrypt. Vendors: PyPI, Jahlives.

Executive brief

openssl_encrypt is a library for encrypting files with password protection and optional recovery credentials. The vulnerability allows an attacker who can modify an encrypted file's header to silently remove recovery slots—backup decryption paths the file owner deliberately added—without needing the password. This could lock the owner out of their own data if their primary password is forgotten and the backup recovery paths have been stripped.

Technical details

The vulnerability is an improper cryptographic signature verification (CWE-347) and integrity check validation failure (CWE-354) in envelope-format encrypted files. In versions before 1.4.9, recovery-slot fields are excluded from the AEAD associated data and the slot-set MAC is only verified when slots are present. An attacker with file modification capability can delete recovery-slot fields from the header without re-encrypting the payload or requiring the password key; the decryption path then proceeds as if no recovery slots ever existed. The fix (1.4.9) binds a recovery-slot-count commitment into the wrapped DEK's AEAD associated data, causing decryption to fail if slots are removed or the count is altered. Note that file modification capability (not network access) is the primary attack vector, and patch 1.4.9 is available.

Affected products

  • jahlives openssl_encrypt before 1.4.9

Timeline

  • 2026-08-12: disclosed: GitHub Security Advisory GHSA-grhj-cpmg-f5mx published
  • 2026-08-27: advisory: CVE-2026-81680 published on NVD

References

Related threats