Количество 41
Количество 41
GHSA-89gr-r52h-f8rx
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
CVE-2026-39831
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
CVE-2026-39831
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
CVE-2026-39831
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
CVE-2026-39831
Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
CVE-2026-39831
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ...
ROS-20260709-80-0027
Уязвимость portainer-ce
ROS-20260709-73-0026
Уязвимость portainer-ce
BDU:2026-11948
Уязвимость функции Verify() языка программирования Go, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
openSUSE-SU-2026:20838-1
Security update for hauler
openSUSE-SU-2026:20833-1
Security update for trivy
openSUSE-SU-2026:21069-1
Security update for google-guest-agent
openSUSE-SU-2026:20834-1
Security update for apptainer
openSUSE-SU-2026:21084-1
Security update for distribution
SUSE-SU-2026:2611-1
Security update for google-osconfig-agent
SUSE-SU-2026:2665-1
Security update for google-osconfig-agent
openSUSE-SU-2026:21281-1
Security update for cosign
openSUSE-SU-2026:20902-1
Security update for keybase-client
SUSE-SU-2026:2827-1
Security update for cosign
SUSE-SU-2026:2609-1
Security update for apptainer
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-89gr-r52h-f8rx golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | CVSS3: 9.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-39831 The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback. | CVSS3: 9.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-39831 The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback. | CVSS3: 8.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-39831 The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback. | CVSS3: 9.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-39831 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh | 0% Низкий | 4 месяца назад | ||
CVE-2026-39831 The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ... | CVSS3: 9.1 | 0% Низкий | 4 месяца назад | |
ROS-20260709-80-0027 Уязвимость portainer-ce | CVSS3: 9.1 | 0% Низкий | 3 месяца назад | |
ROS-20260709-73-0026 Уязвимость portainer-ce | CVSS3: 9.1 | 0% Низкий | 3 месяца назад | |
BDU:2026-11948 Уязвимость функции Verify() языка программирования Go, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 9.1 | 0% Низкий | 4 месяца назад | |
openSUSE-SU-2026:20838-1 Security update for hauler | 4 месяца назад | |||
openSUSE-SU-2026:20833-1 Security update for trivy | 4 месяца назад | |||
openSUSE-SU-2026:21069-1 Security update for google-guest-agent | 3 месяца назад | |||
openSUSE-SU-2026:20834-1 Security update for apptainer | 4 месяца назад | |||
openSUSE-SU-2026:21084-1 Security update for distribution | 3 месяца назад | |||
SUSE-SU-2026:2611-1 Security update for google-osconfig-agent | 3 месяца назад | |||
SUSE-SU-2026:2665-1 Security update for google-osconfig-agent | 3 месяца назад | |||
openSUSE-SU-2026:21281-1 Security update for cosign | 2 месяца назад | |||
openSUSE-SU-2026:20902-1 Security update for keybase-client | 4 месяца назад | |||
SUSE-SU-2026:2827-1 Security update for cosign | 3 месяца назад | |||
SUSE-SU-2026:2609-1 Security update for apptainer | 3 месяца назад |
Уязвимостей на страницу