Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-39831

Опубликовано: 22 мая 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:golang:crypto:*:*:*:*:*:go:*:*
Версия до 0.52.0 (исключая)

EPSS

Процентиль: 35%
0.0042
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 8.1
redhat
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

msrc
2 месяца назад

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

CVSS3: 9.1
debian
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ...

CVSS3: 9.1
redos
22 дня назад

Уязвимость portainer-ce

EPSS

Процентиль: 35%
0.0042
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-862