UNKNOWN PyPI
CVE-2026-81691
PYSEC-2026-3797 · CVE-2026-81691 · GHSA-xr64-hcxg-4ghr
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover.
Ready to move
Start Securing
Free, no credit card | First findings in minutes