CVE-2026-81688: Insecure Plaintext Hash Metadata

Storing an unkeyed plaintext hash (such as 'original_hash' or 'plaintext_hash') in metadata headers allows offline plaintext confirmation and cross-file correlation without the decryption key.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-81688-insecure-plaintext-hash-metadata --engine opengrep

Description

Storing an unkeyed plaintext hash (such as 'original_hash' or 'plaintext_hash') in metadata headers allows offline plaintext confirmation and cross-file correlation without the decryption key.