From 680f5dae7cad904dab377264712c982361c6ba66 Mon Sep 17 00:00:00 2001 From: Jonathan White Date: Mon, 9 Mar 2026 18:42:25 -0400 Subject: [PATCH] Security: Prevent loading of openssl.cnf (#13118) * Security: Prevent loading of openssl.cnf Prevent loading openssl.cnf from the originating vcpkg folder tree to avoid DLL injections. This patch force sets the OPENSSL_CONF and OPENSSL_MODULES env vars to an invalid directory. This prevents openssl from attempting to load a cnf file which can contain settings to load arbitrary DLL files into KeePassXC memory space. Thank you to zdi-disclosures for reporting this finding! --- src/main.cpp | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/src/main.cpp b/src/main.cpp index 2c4da4c1f..cb7cb18f9 100644 --- a/src/main.cpp +++ b/src/main.cpp @@ -53,6 +53,13 @@ int main(int argc, char** argv) { QT_REQUIRE_VERSION(argc, argv, QT_VERSION_STR) +#ifdef Q_OS_WIN + // Set OPENSSL_CONF and OPENSSL_MODULES to an invalid location to prevent DLL injection via openssl.cnf. + // vcpkg by default hard-codes this to its packages location, which may be user-writable. + qputenv("OPENSSL_CONF", "::"); + qputenv("OPENSSL_MODULES", "::"); +#endif + QApplication::setAttribute(Qt::AA_EnableHighDpiScaling); QGuiApplication::setAttribute(Qt::AA_UseHighDpiPixmaps); #if QT_VERSION >= QT_VERSION_CHECK(5, 14, 0) && defined(Q_OS_WIN)