CVE-2026-39831

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/05/2026
Last modified:
02/06/2026

Description

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:golang:crypto:*:*:*:*:*:go:*:* 0.52.0 (excluding)