CVE-2026-81699: Openssl Encrypt Unbounded Recovery Slots

Envelope decryption recovery slots from untrusted metadata are processed without validating against a maximum slot count limit. An attacker can supply a crafted file with numerous recovery slots to cause pre-authentication CPU and memory exhaustion (DoS).

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-81699-openssl-encrypt-unbounded-recovery-slots --engine opengrep

Description

Envelope decryption recovery slots from untrusted metadata are processed without validating against a maximum slot count limit. An attacker can supply a crafted file with numerous recovery slots to cause pre-authentication CPU and memory exhaustion (DoS).