openssl-encrypt vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-C65F-X25W-62JVMediumopenssl-encrypt: openssl-encrypt has CORS wildcard with allow_credentials=True in standalone serversGHSA-4RH7-JWG9-M28MMediumopenssl-encrypt: openssl-encrypt accepts refresh tokens as URL query parameters causing token leakageGHSA-2VHW-Q7VH-7XV2Mediumopenssl-encrypt: openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callersGHSA-HVC7-763R-4F3HMediumopenssl-encrypt: openssl-encrypt has no owner verification on key revocation — any client can revoke any keyGHSA-8H88-GXP3-J7PGMediumopenssl-encrypt: openssl-encrypt's unverified key bundle from_dict() + to_identity() path allows encryption to attacker keysGHSA-425G-FJHQ-5H92Mediumopenssl-encrypt: openssl-encrypt silently skips schema validation when jsonschema library is not installedGHSA-VFGX-5Q85-58Q3Mediumopenssl-encrypt: openssl-encrypt has non-cryptographic PRNG used for steganography pixel selectionGHSA-H3M5-P59H-X88PMediumopenssl-encrypt: openssl-encrypt has visible password in process list via --password CLI argumentGHSA-H45M-MGCP-Q388Criticalopenssl-encrypt: openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restartGHSA-J48Q-4C78-RHF9Mediumopenssl-encrypt: openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification

Stop the waste.
Protect your environment with Kodem.