云虫漏洞情报

CVE-2026-81693 - openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions. - 漏洞详情

漏洞编号:CVE-2026-81693

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-81693

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-789

发布/更新时间:2026-08-27 / 2026-08-28

漏洞描述

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions.

相关链接

相关漏洞

« 返回首页