PYSEC-2026-3781

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/openssl-encrypt/PYSEC-2026-3781.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3781
Aliases
Published
2026-08-27T17:21:01.293Z
Modified
2026-09-02T09:00:04.193811875Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes visible and resolves to the attacker's keys, enabling silent key substitution for encrypted files.

References

Affected packages

PyPI / openssl-encrypt

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.9

Affected versions

0.*
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.3.0
0.3.1
0.3.2
0.3.3
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.5.0
0.5.1
0.5.3
0.6.0rc1
0.7.0rc2
0.7.1
0.7.2
0.8.0
0.8.1
0.8.2
0.9.2
1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0b3
1.4.0b4
1.4.0b5
1.4.0b6
1.4.0b7
1.4.0b8
1.4.0
1.4.1rc2
1.4.1
1.4.2
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/openssl-encrypt/PYSEC-2026-3781.yaml"