Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-39831

Опубликовано: 27 мая 2026
Источник: msrc
CVSS3: 9.1
EPSS Низкий

Описание

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

EPSS

Процентиль: 30%
0.00373
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 9.1
nvd
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 9.1
debian
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ...

suse-cvrf
2 месяца назад

Security update for hauler

suse-cvrf
2 месяца назад

Security update for trivy

EPSS

Процентиль: 30%
0.00373
Низкий

9.1 Critical

CVSS3