CVE-2026-81700
opensslencrypt versions before 1.4.9 contain a signature verification vulnerability in gpgrunner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing keys or expired project keys can bypass signature verification to execute malicious plugins in the host process.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81700.json, https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-x38r-8wf3-q9hq, https://nvd.nist.gov/vuln/detail/CVE-2026-81700, https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-gpg-signature-verification-bypass