top of page
perceptive_background_267k.jpg

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only…

Published:

27 August 2026 at 00:00:00

Alert date:

27 August 2026 at 20:17:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Security Tools

openssl_encrypt versions prior to 1.4.9 contain a critical signature verification vulnerability in the gpg_runner.verify_detached function. The flaw arises from only checking the VALIDSIG status while ignoring REVKEYSIG, EXPKEYSIG statuses and GPG exit codes. This oversight allows attackers who possess revoked or expired signing keys to bypass signature verification entirely. Successful exploitation enables the execution of malicious plugins within the host process. The vulnerability poses a significant risk as it undermines the integrity of the plugin loading mechanism. Users are advised to upgrade to version 1.4.9 or later to remediate the issue.

Technical details

Mitigation steps:

Affected products:

openssl_encrypt (versions before 1.4.9)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page