CVE-2026-81699: Openssl Encrypt Unbounded Recovery Slotscve-2026-81699-openssl-encrypt-unbounded-recovery-slots
Envelope decryption recovery slots from untrusted metadata are processed without validating against a maximum slot count limit. An attacker can supply a crafted file with numerous recovery slots to cause pre-authentication CPU and memory exhaustion (DoS).