VDB

CVE-2026-39833

CVE-2026-39833 PUBLISHED CVSS 9.300000190734863 CRITICAL

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.

EPSS 0.04% · 13.1th percentile

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.04%
13.1th percentile

Affected Products

VendorProductVersions
golang.org/x/cryptogolang.org/x/crypto/ssh/agent0

Timeline

  • May 22, 2026 EPSS Score
  • May 22, 2026 Coalition ESS Score
  • May 22, 2026 CVE Published
  • May 22, 2026 PoC Published
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 25, 2026 Security Advisory
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
  • May 28, 2026 EPSS Score
  • May 29, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›