CVE-2026-46728
published 2026-05-16CVE-2026-46728: Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
PriorityP344high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.16%
5.5th percentile
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| denx | u-boot | < 2026.04 | 2026.04 |
| denx | u-boot | 2013.07 – 2025.10 | — |
| pengutronix | barebox | >= 2016.03.0 < 2025.09.3 | 2025.09.3 |
| pengutronix | barebox | >= 2025.10.0 < 2026.03.1 | 2026.03.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5cv5-vm4q-7wmx: Das U-Boot before 2026
ghsa_unreviewed·2026-05-17
CVE-2026-46728 [HIGH] CWE-346 GHSA-5cv5-vm4q-7wmx: Das U-Boot before 2026
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
VulDB
barebox up to 2025.09.2/2026.03.0 data authenticity (Duplicate CVE-2026-46728 / GHSA-3fvj-q26p-j6h4)
vuldb·2026-05-17·CVSS 8.2
CVE-2026-33243 [HIGH] barebox up to 2025.09.2/2026.03.0 data authenticity (Duplicate CVE-2026-46728 / GHSA-3fvj-q26p-j6h4)
A vulnerability was found in barebox up to 2025.09.2/2026.03.0. It has been declared as critical. Impacted is an unknown function. The manipulation results in insufficient verification of data authenticity.
This vulnerability is reported as CVE-2026-33243. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
A duplicate CVE-2026-46728 appears to be assigned to this entry.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-16
Published