Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 34

Количество 34

github логотип

GHSA-89gr-r52h-f8rx

около 1 месяца назад

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2026-39831

2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-39831

2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-39831

2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2026-39831

2 месяца назад

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

EPSS: Низкий
debian логотип

CVE-2026-39831

2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ...

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260709-73-0026

22 дня назад

Уязвимость portainer-ce

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20838-1

2 месяца назад

Security update for hauler

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20833-1

2 месяца назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21069-1

около 1 месяца назад

Security update for google-guest-agent

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20834-1

2 месяца назад

Security update for apptainer

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21084-1

около 1 месяца назад

Security update for distribution

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2611-1

около 1 месяца назад

Security update for google-osconfig-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2665-1

около 1 месяца назад

Security update for google-osconfig-agent

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21281-1

21 день назад

Security update for cosign

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20902-1

около 2 месяцев назад

Security update for keybase-client

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2827-1

21 день назад

Security update for cosign

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2609-1

около 1 месяца назад

Security update for apptainer

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21244-1

25 дней назад

Security update for podman

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21120-1

около 1 месяца назад

Security update for mcphost

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-89gr-r52h-f8rx

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-39831

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 9.1
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-39831

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 8.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-39831

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 9.1
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-39831

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

0%
Низкий
2 месяца назад
debian логотип
CVE-2026-39831

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ...

CVSS3: 9.1
0%
Низкий
2 месяца назад
redos логотип
ROS-20260709-73-0026

Уязвимость portainer-ce

CVSS3: 9.1
0%
Низкий
22 дня назад
suse-cvrf логотип
openSUSE-SU-2026:20838-1

Security update for hauler

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20833-1

Security update for trivy

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21069-1

Security update for google-guest-agent

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20834-1

Security update for apptainer

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21084-1

Security update for distribution

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2611-1

Security update for google-osconfig-agent

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2665-1

Security update for google-osconfig-agent

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21281-1

Security update for cosign

21 день назад
suse-cvrf логотип
openSUSE-SU-2026:20902-1

Security update for keybase-client

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2827-1

Security update for cosign

21 день назад
suse-cvrf логотип
SUSE-SU-2026:2609-1

Security update for apptainer

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21244-1

Security update for podman

25 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21120-1

Security update for mcphost

около 1 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.