criticalCVSS 9.1Vulnerability

CVE-2026-42508

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

Properties

severity
critical
summary
golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status
epss_score
0.00568
cvss_score
9.1
ghsa_published
2026-06-25T22:22:04Z
source_url
https://github.com/advisories/GHSA-5cgq-3rg8-m6cv
ghsa_updated
2026-07-01T15:35:58Z
ghsa_id
GHSA-5cgq-3rg8-m6cv
cve_id
CVE-2026-42508
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
false
epss_percentile
0.43965

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]go/golang.org/x/crypto/ssh/knownhosts

AFFECTS (1)

[Software]go/golang.org/x/crypto/ssh/knownhosts

HAS_WEAKNESS (1)

[Weakness]Improper Certificate Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-42508 (CVSS 9.1) — Ninja Signal Threat Intelligence | Ninja Signal