Junglewise Threat Intelligence

CVE-2026-81691: openssl_encrypt unvalidated server URL in login and register_with_email

CVE-2026-81691 · Severity: high · CVSS 7.5 · Published 2026-08-27

Technologies: openssl-encrypt (PyPI), Openssl Encrypt. Vendors: PyPI, Jahlives.

Executive brief

openssl_encrypt is a library for secure credential storage and key management in applications. Versions before 1.4.9 fail to validate server URLs in login and email registration functions, allowing them to accept unencrypted HTTP connections. Attackers positioned on the network can intercept transmitted credentials—including access tokens, passwords, and JWTs—leading to complete account takeover and unauthorized access to a user's cryptographic keys.

Technical details

The vulnerability is a cleartext transmission issue (CWE-319) in the keyserver plugin's login() and register_with_email() functions. While register() enforces HTTPS, login() and register_with_email() do not validate that the server URL uses HTTPS or matches the configured servers; certificate pinning is only applied when the HTTPS prefix is present. An attacker positioned on the network path can intercept credentials sent in cleartext over HTTP, including client_id (which alone grants access/refresh tokens), stored passwords, and returned JWTs, achieving full account takeover. The fix in version 1.4.9 introduces a shared _validate_server_url() validator that enforces HTTPS and membership in config.servers before any request is constructed, preventing credential leakage by refusing to make requests to invalid endpoints.

Affected products

  • openssl_encrypt openssl_encrypt before 1.4.9

Timeline

  • 2026-08-12: disclosed: GitHub Security Advisory (GHSA-xr64-hcxg-4ghr) published
  • 2026-08-27: advisory: CVE-2026-81691 and NVD entry published
  • 2026: patched: Version 1.4.9 released with fix

References

Related threats