CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-39831

Critical · CVSS 9.1
CVSS
9.1
nvd
EPSS
0.37%
30th pct
KEV
No
Class
oss containerizable
CWE-862

Description

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

Affected packages

Go golang.org/x/crypto 0 → 0.52.0

References

Status: profiled · ingested 2026-07-23T18:00:18.000Z