VDB
CVE-2026-39833
CVE-2026-39833
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.
EPSS 0.04% · 13.1th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.04%
13.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| golang.org/x/crypto | golang.org/x/crypto/ssh/agent | 0 |
Timeline
- May 22, 2026 EPSS Score
- May 22, 2026 Coalition ESS Score
- May 22, 2026 CVE Published
- May 22, 2026 PoC Published
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 25, 2026 Security Advisory
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
- May 28, 2026 EPSS Score
- May 29, 2026 EPSS Score