Junglewise Threat Intelligence

CVE-2026-81688: openssl_encrypt plaintext confirmation oracle via unkeyed SHA-256

CVE-2026-81688 · Severity: high · CVSS 7.5 · Published 2026-08-27

Technologies: openssl-encrypt (PyPI), Openssl Encrypt. Vendors: PyPI, Jahlives.

Executive brief

openssl_encrypt is a Python library for encrypting files. Versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the file header, allowing attackers to confirm guessed passwords offline or identify identical files across multiple backups without ever knowing the encryption key. This undermines the confidentiality protections of the encryption.

Technical details

The vulnerability is a missing encryption of sensitive data (CWE-311) in which every encrypted file contains hashes.original_hash = SHA-256(plaintext) in the cleartext file header metadata. Because the hash is unkeyed and readable without the password, an attacker can perform offline plaintext confirmation by hashing candidate plaintexts and comparing them to the stored hash, or fingerprint identical plaintexts across separately encrypted files. The hash is cryptographically redundant because the cipher already authenticates plaintext via AEAD tags, Fernet HMAC, Camellia encrypt-then-MAC, or other mechanisms. Fix: version 1.4.9 removes the unkeyed plaintext hash from all encryption paths; decryption remains tolerant of legacy files that still contain it.

Affected products

  • openssl_encrypt openssl_encrypt before 1.4.9

Timeline

  • 2026-08-12: disclosed
  • 2026-08-12: patched: patched in version 1.4.9
  • 2026-08-27: advisory

References

Related threats