CVE-2026-39831

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
Configurations

Configuration 1 (hide)

cpe:2.3:a:golang:crypto:*:*:*:*:*:go:*:*

History

No history.

Information

Published : 2026-05-22 04:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-39831

Mitre link : CVE-2026-39831

CVE.ORG link : CVE-2026-39831


JSON object : View

Products Affected

golang

  • crypto
CWE
CWE-862

Missing Authorization