VulnSea

jahlives has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 7. The median CVSS is 6.2 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.2
Publish → KEV
Last 90 days
7 prev 0

Products

  • openssl_encrypt 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

jahlives vulnerabilities

CVEs affecting jahlives, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-81720Medium· 6.2
3w ago

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity st…

Sunlitjahlives · openssl_encryptEPSS 0.13%via NVD
CVE-2026-81684Medium· 6.2
3w ago

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and decrypt paths) inst…

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and decrypt paths) inst…

Sunlitjahlives · openssl_encryptEPSS 0.12%via NVD
CVE-2026-81715Low· 3.3
3w ago

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to saniti…

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to saniti…

Sunlitjahlives · openssl_encryptEPSS 0.19%via NVD
CVE-2026-81699High· 7.5
3w ago

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply …

Twilightjahlives · openssl_encryptEPSS 0.35%via NVD
CVE-2026-81704High· 7.5
3w ago

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against e…

Twilightjahlives · openssl_encryptEPSS 0.20%via NVD
CVE-2026-74871Medium· 6.2
1mo ago

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can by…

Sunlitjahlives · openssl_encryptEPSS 0.08%via NVD
CVE-2026-74881Medium· 6.5⚖ disputed
1mo ago

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of …

Sunlitjahlives · openssl_encryptEPSS 0.25%via NVD
jahlives vulnerabilities (CVEs) · VulnSea