Executive brief
openssl-encrypt is a Python library for plugin signing and trust-anchor management. Versions 1.4.8 and earlier accept partial GPG key fingerprints during trust enrollment, allowing an attacker to forge a short (32-bit) key ID that collides with a legitimate key. Once enrolled, the attacker's key can sign malicious plugins that are trusted by the system, leading to arbitrary code execution through the ENFORCE signature policy.
Technical details
The vulnerability is an improper cryptographic signature verification flaw (CWE-347) in the enroll_trust_key function. It uses suffix-tolerant fingerprint matching instead of requiring exact full-fingerprint validation, allowing an operator to confirm only a short, forgeable GPG key ID. An attacker can generate a colliding key with the same short ID, enroll it as a trusted anchor, and use it to sign malicious plugins that pass validation under the ENFORCE policy. The attack requires operator interaction to confirm the fingerprint but exploits the partial-match acceptance to bypass key verification. Version 1.4.9 fixes this by enforcing exact full primary-key fingerprint matches (case-insensitive, whitespace-stripped) and rejecting partial confirmations.
Affected products
- openssl-encrypt openssl-encrypt 0 to 1.4.8
Timeline
- 2026-08-27: disclosed
- 2026-08-12: patched: Version 1.4.9 released with fix