Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89gr-r52h-f8rx

Опубликовано: 25 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

Пакеты

Наименование

golang.org/x/crypto

go
Затронутые версииВерсия исправления

< 0.52.0

0.52.0

EPSS

Процентиль: 35%
0.0042
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 8.1
redhat
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 9.1
nvd
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

msrc
2 месяца назад

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

CVSS3: 9.1
debian
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ...

EPSS

Процентиль: 35%
0.0042
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-862