| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Python products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-81721 | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malic... | 7.5 | 386 | Neutral | No |
| Yes |
| CVE-2026-81719 | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compi... | 7.8 | 594 | Neutral | No | Yes |
| CVE-2026-81717 | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical... | 3.5 | 102 | Neutral | No | Yes |
| CVE-2026-81716 | openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed pl... | 5.2 | 238 | Neutral | No | Yes |
| CVE-2026-81714 | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forg... | 7.0 | 287 | Neutral | No | Yes |
| CVE-2026-81706 | openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corre... | 6.8 | 253 | Neutral | No | Yes |
| CVE-2026-81705 | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option sp... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-81703 | openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decry... | 5.5 | 125 | Neutral | No | Yes |
| CVE-2026-81701 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature ve... | 9.8 | 588 | Neutral | No | Yes |
| CVE-2026-81700 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspec... | 9.8 | 588 | Neutral | No | Yes |
| CVE-2026-81698 | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can c... | 8.8 | 708 | Neutral | No | Yes |
| CVE-2026-81696 | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape sequences to repa... | 3.3 | 95 | Neutral | No | Yes |
| CVE-2026-81695 | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id contai... | 3.3 | 95 | Neutral | No | Yes |
| CVE-2026-81693 | openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger un... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-81691 | openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path ... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-81690 | openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not desce... | 7.3 | 349 | Neutral | No | Yes |
| CVE-2026-81688 | openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plainte... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-81686 | openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any lo... | 5.5 | 211 | Neutral | No | Yes |
| CVE-2026-81685 | openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal conf... | 3.3 | 95 | Neutral | No | Yes |
| CVE-2026-81683 | openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Setti... | 5.5 | 125 | Neutral | No | Yes |