CVE-2026-42508
Critical · CVSS 9.1Go (golang) crypto/ssh — Improper Certificate Validation / Revoked SignatureKey not checked (CWE-295)
- CVSS
- 9.1
- nvd
- EPSS
- 0.57%
- 44th pct
- KEV
- No
- Class
- oss containerizable
- CWE-295, CWE-295
Description
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
Search profile — drives PoC discovery
Symbols SignatureKeykey.SignatureKey@revokedCertCheckerIsRevokedRevokedCertscheckCertCheckCert
Keywords CVE-2026-42508GO-2026-5021golang crypto/ssh revoked SignatureKeygolang ssh CA certificate revocation bypasscrypto/ssh CertChecker revocationgolang ssh SignatureKey revoked checkRHSA-2026:23262
Versions: Go versions prior to the fix in CL 781220 (see go.dev/issue/79568)
Affected packages
| Go | golang.org/x/crypto | 0 → 0.52.0 |
References
- https://go.dev/cl/781220
- https://go.dev/issue/79568
- https://groups.google.com/g/golang-announce/c/a082jnz-LvI
- https://pkg.go.dev/vuln/GO-2026-5021
- https://access.redhat.com/errata/RHSA-2026:23262
- https://access.redhat.com/errata/RHSA-2026:23264
- https://access.redhat.com/errata/RHSA-2026:26546
- https://access.redhat.com/errata/RHSA-2026:26547
- https://access.redhat.com/errata/RHSA-2026:35833
- https://access.redhat.com/errata/RHSA-2026:36648
- https://access.redhat.com/errata/RHSA-2026:36651
- https://access.redhat.com/errata/RHSA-2026:36796
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z