CVE-2026-39831
published 2026-05-22CVE-2026-39831: The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag…
PriorityP352critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.49%
39.4th percentile
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Affected
184 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-rhel8-operator | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-rhel8_1782891812 | — | — |
| advanced-cluster-security | rhacs-scanner-slim-rhel8_1782891812 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel8_1783357116 | — | — |
| assisted | agent-preinstall-image-builder-rhel9 | — | — |
| buildah_project | buildah | — | — |
| cert-manager | jetstack-cert-manager-acmesolver-rhel9 | — | — |
| cert-manager | jetstack-cert-manager-rhel9 | — | — |
| compliance | openshift-security-profiles-operator-bundle | — | — |
| compliance | openshift-security-profiles-rhel8-operator | — | — |
| confidential-containers | trustee | — | — |
| container-native-virtualization | virt-api-rhel9 | — | — |
| container-native-virtualization | virt-artifacts-server-rhel9 | — | — |
| container-native-virtualization | virt-controller-rhel9 | — | — |
| container-native-virtualization | virt-exportproxy-rhel9 | — | — |
| container-native-virtualization | virt-exportserver-rhel9 | — | — |
| container-native-virtualization | virt-handler-rhel9 | — | — |
| container-native-virtualization | virt-launcher-rhel9 | — | — |
| container-native-virtualization | virt-operator-rhel9 | — | — |
| container-tools_rhel8 | buildah | — | — |
| container-tools_rhel8 | podman | — | — |
| cryostat | cryostat-storage-rhel9 | — | — |
| devspaces | traefik-rhel9 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed
ghsa·2026-06-25
CVE-2026-39831 [CRITICAL] CWE-862 golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed
golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
VulDB
x-crypto up to 0.51.x FIDO/U2F Verify authentication spoofing (EUVD-2026-31395 / WID-SEC-2026-1653)
vuldb·2026-05-23
CVE-2026-39831 [CRITICAL] x-crypto up to 0.51.x FIDO/U2F Verify authentication spoofing (EUVD-2026-31395 / WID-SEC-2026-1653)
A vulnerability, which was classified as critical, has been found in x-crypto up to 0.51.x. This impacts the function Verify of the component FIDO/U2F. Performing a manipulation results in authentication bypass by spoofing.
This vulnerability is identified as CVE-2026-39831. The attack may be carried out on the physical device. There is not any exploit available.
It is advisable to upgrade the affected component.
Ubuntu
Google Guest Agent vulnerabilities
vendor_ubuntu·2026-06-22·CVSS 9.1
CVE-2026-39831 [CRITICAL] Google Guest Agent vulnerabilities
Title: Google Guest Agent vulnerabilities
Summary: Several security issues were fixed in Google Guest Agent.
USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides
the corresponding updates for Go Cryptography code embedded in Google
Guest Agent.
Original advisory details:
It was discovered that Go Cryptography did not properly handle SSH global
request responses. A remote attacker could possibly use this issue to cause
a denial of service. (CVE-2026-39830)
It was discovered that Go Cryptography did not properly verify user
presence when using FIDO/U2F security keys. An attacker could possibly use
this issue to bypass user presence verification for hardware security keys.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04
Ubuntu
LXD vulnerabilities
vendor_ubuntu·2026-06-18·CVSS 9.1
CVE-2026-39830 [CRITICAL] LXD vulnerabilities
Title: LXD vulnerabilities
Summary: Several security issues were fixed in LXD.
USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides
the corresponding updates for Go Cryptography code embedded in LXD for
CVE-2026-39830, CVE-2026-39833, CVE-2026-39834, and CVE-2026-42508.
Original advisory details:
It was discovered that Go Cryptography did not properly handle SSH global
request responses. A remote attacker could possibly use this issue to cause
a denial of service. (CVE-2026-39830)
It was discovered that Go Cryptography did not properly verify user
presence when using FIDO/U2F security keys. An attacker could possibly use
this issue to bypass user presence verification for hardware security keys.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 2
Red Hat
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
vendor_redhat·2026-05-22·CVSS 9.1
CVE-2026-39831 [CRITICAL] CWE-347 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
A flaw was found in golang.org/x/crypto/ssh. The Verify() method, responsible for FIDO/U2F security key types, did not properly check for user presence. This allowed signatures to be accepted without requiring a physical touch on the hardware security key. As a result, an attacker could potentially use
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-39831 vagrant: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 vagrant: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 vagrant: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 cri-o1.32: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 cri-o1.32: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 cri-o1.32: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 apptainer: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 apptainer: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 apptainer: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 DankMaterialShell: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 DankMaterialShell: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 DankMaterialShell: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 containers-common: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 containers-common: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 containers-common: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 kubernetes1.34: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 kubernetes1.34: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 kubernetes1.34: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 podman-tui: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 podman-tui: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 podman-tui: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 transifex-client: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 transifex-client: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 transifex-client: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 docker-buildx: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 docker-buildx: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 docker-buildx: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 opentofu: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 opentofu: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 opentofu: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 cri-o1.34: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 cri-o1.34: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 cri-o1.34: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 forgejo-runner: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 forgejo-runner: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 forgejo-runner: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 cri-o: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 cri-o: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 cri-o: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 pack: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 pack: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 pack: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 cri-o1.33: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 cri-o1.33: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 cri-o1.33: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 cheat: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 cheat: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 cheat: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 kubernetes1.36: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 kubernetes1.36: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 kubernetes1.36: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 forgejo: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 forgejo: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 forgejo: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 age: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 age: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 age: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 rclone: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 rclone: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 rclone: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 gvisor-tap-vsock: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 gvisor-tap-vsock: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 gvisor-tap-vsock: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 prometheus-podman-exporter: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 prometheus-podman-exporter: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 prometheus-podman-exporter: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 opkssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 opkssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 opkssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 doctl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 doctl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 doctl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 jfrog-cli: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 jfrog-cli: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 jfrog-cli: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 cri-o1.35: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 cri-o1.35: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 cri-o1.35: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 incus: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 incus: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 incus: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 singularity-ce: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 singularity-ce: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 singularity-ce: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 restic: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 restic: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 restic: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 gopass: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 gopass: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 gopass: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 cri-o1.31: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 cri-o1.31: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 cri-o1.31: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 rootlesskit: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 rootlesskit: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 rootlesskit: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 apptainer: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 apptainer: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 apptainer: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 matterbridge: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 matterbridge: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 matterbridge: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 forgejo: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 forgejo: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 forgejo: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 trivy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 trivy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 trivy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 clash-meta: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 clash-meta: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 clash-meta: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 kubernetes1.31: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 kubernetes1.31: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 kubernetes1.31: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 caddy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 caddy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 caddy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 cri-o1.30: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 cri-o1.30: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 cri-o1.30: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 openbao: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 openbao: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 openbao: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 trayscale: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 trayscale: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 trayscale: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 nebula: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 nebula: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 nebula: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang-github-git-5: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang-github-git-5: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 golang-github-git-5: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 vhs: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 vhs: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 vhs: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 google-guest-agent: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 google-guest-agent: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 google-guest-agent: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 ollama: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 ollama: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 ollama: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang-x-crypto: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang-x-crypto: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 golang-x-crypto: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 nuclei: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 nuclei: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 nuclei: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 trivy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 trivy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 trivy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 kubernetes1.32: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 kubernetes1.32: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 kubernetes1.32: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 age: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 age: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 age: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 kubernetes1.35: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 kubernetes1.35: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 kubernetes1.35: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 kubernetes1.30: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 kubernetes1.30: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 kubernetes1.30: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 complyctl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 complyctl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 complyctl: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 docker-compose: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 docker-compose: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 docker-compose: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 nng: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 nng: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 nng: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang-github-acme-lego: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang-github-acme-lego: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 golang-github-acme-lego: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 buildah: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 buildah: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 buildah: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Discussion:
buildah does not act as an SSH server verifying client
Bugzilla
CVE-2026-39831 clash-meta: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 clash-meta: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 clash-meta: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 kubernetes1.33: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 kubernetes1.33: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 kubernetes1.33: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 gh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 gh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 gh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 inspektor-gadget: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 inspektor-gadget: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 inspektor-gadget: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 rclone: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 rclone: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 rclone: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 docker-buildkit: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 docker-buildkit: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 docker-buildkit: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 restic: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 restic: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 restic: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 podman-tui: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 podman-tui: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 podman-tui: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 chezmoi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 chezmoi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 chezmoi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 headscale: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 headscale: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 headscale: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 pack: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 pack: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 pack: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 tailscale: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 tailscale: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 tailscale: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 forgejo-runner: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 forgejo-runner: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 forgejo-runner: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 prometheus-podman-exporter: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 prometheus-podman-exporter: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 prometheus-podman-exporter: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 matterbridge: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 matterbridge: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 matterbridge: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 nuclei: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 nuclei: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 nuclei: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 gh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 gh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 gh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 chezmoi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 chezmoi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 chezmoi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 jfrog-cli: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 jfrog-cli: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 jfrog-cli: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang-x-crypto: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang-x-crypto: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 golang-x-crypto: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 openbao: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 openbao: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 openbao: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 moby-engine: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 moby-engine: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 moby-engine: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Discussion:
cli [ 29.x] Elapsed: 2s
❯ go mod why -m golang.or
Bugzilla
CVE-2026-39831 gopass-jsonapi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 gopass-jsonapi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 gopass-jsonapi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 gopass-hibp: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 gopass-hibp: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 gopass-hibp: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 k9s: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 k9s: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 k9s: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 caddy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 caddy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
CVE-2026-39831 caddy: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 podman: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 podman: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 podman: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Discussion:
Fixed in podman-5.8.4-1.fc43 and podman-5.8.4-1.fc44 (g
Bugzilla
CVE-2026-39831 singularity-ce: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 singularity-ce: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 singularity-ce: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 hcloud: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 hcloud: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 hcloud: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 opkssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
bugzilla·2026-07-30·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 opkssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
CVE-2026-39831 opkssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Bugzilla
CVE-2026-39831 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
bugzilla·2026-05-22·CVSS 9.1
CVE-2026-39831 [CRITICAL] CVE-2026-39831 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
CVE-2026-39831 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check
The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
2026-05-22
Published