---
id: CVE-2026-81707
title: >-
  openssl_encrypt before 1.4.9 fails to sanitize the email field of imported
  identity documents, allowing attackers to inject ANSI escape sequences that
  forge the fingerprint verification line displayed to users
summary: >-
  openssl_encrypt before 1.4.9 fails to sanitize the email field of imported
  identity documents, allowing attackers to inject ANSI escape sequences that
  forge the fingerprint verification line displayed to users. Attackers can
  deliver a cr…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
published: '2026-08-27'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:42.730'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81707'
references:
  - url: >-
      https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-qjr2-x6mr-8xgf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-ansi-escape-injection-via-identity-email
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00587
epssPercentile: 0.4571
ingestedAt: '2026-09-23T17:28:14.809Z'
---

## Overview

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing the out-of-band verification mechanism that protects against key substitution attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
