UNKNOWN PyPI

CVE-2026-81691

PYSEC-2026-3797 · CVE-2026-81691 · GHSA-xr64-hcxg-4ghr

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover.

Ready to move

Start Securing

Free, no credit card | First findings in minutes