Executive brief
openssl_encrypt is a Python library for encrypting and decrypting files using password-based key derivation. An attacker can craft a malicious encrypted file that declares extremely large memory-hard key derivation function (KDF) parameters, causing the decryption process to allocate gigabytes to terabytes of memory before the password is even validated. This allows an unauthenticated attacker to crash the application or entire system without needing the correct password.
Technical details
The vulnerability exists in openssl_encrypt versions before 1.4.9, which fails to validate KDF cost parameters (such as Argon2 memory_cost, scrypt N, or balloon space_cost) when reading encrypted file metadata and keystore headers. An attacker can craft a malicious encrypted file declaring arbitrarily large memory-hard KDF parameters that are consumed during the key derivation phase, before any password authentication occurs. This pre-authentication memory exhaustion triggers unbounded allocation of gigabytes to terabytes of RAM, causing an out-of-memory crash with no authentication required. The fix applies a memory ceiling (default 8 GiB, configurable via --allow-high-kdf-cost flag) to both file decryption and keystore load operations.
Affected products
- openssl_encrypt (jahlives) openssl_encrypt before 1.4.9
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: version 1.4.9 released with fix