GHSA-pr7j-w8v9-qr7rHighCVSS 7.5

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the...

Published
August 27, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or fingerprint identical plaintexts across separately-encrypted files.

🔗 References (4)