CVE-2026-42508 PUBLISHED

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

Assigner: Go
Reserved: 28.04.2026 Published: 22.05.2026 Updated: 22.05.2026

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

Product Status

Vendor golang.org/x/crypto
Product golang.org/x/crypto/ssh/knownhosts
Versions Default: unaffected
  • affected from 0 to 0.52.0 (excl.)

References

Problem Types

  • CWE-295: Improper Certificate Validation