CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-42508

Critical · CVSS 9.1

Go (golang) crypto/ssh — Improper Certificate Validation / Revoked SignatureKey not checked (CWE-295)

CVSS
9.1
nvd
EPSS
0.57%
44th pct
KEV
No
Class
oss containerizable
CWE-295, CWE-295

Description

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

Search profile — drives PoC discovery

Symbols SignatureKeykey.SignatureKey@revokedCertCheckerIsRevokedRevokedCertscheckCertCheckCert
Keywords CVE-2026-42508GO-2026-5021golang crypto/ssh revoked SignatureKeygolang ssh CA certificate revocation bypasscrypto/ssh CertChecker revocationgolang ssh SignatureKey revoked checkRHSA-2026:23262
Versions: Go versions prior to the fix in CL 781220 (see go.dev/issue/79568)

Affected packages

Go golang.org/x/crypto 0 → 0.52.0

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z