Vulnerability intelligence
CVE-2026-39831 — Security Advisory
CVE-2026-39831 (CVSS 9.1): the Verify() method for FIDO/U2F key types in golang.org/x/crypto/ssh never checked the User Presence flag. An attacker with agent access could authenticate silently, defeating the one guarantee hardware keys exist to enforce.
CVSS 9.1
2026
What WebPulse reported · 2 analyses
Go’s SSH Library Accepted Hardware Key Signatures Without Requiring a Touch
CVE-2026-39831 (CVSS 9.1): the Verify() method for FIDO/U2F key types in golang.org/x/crypto/ssh never checked the User Presence flag. An attacker with agent ac
July 15, 2026
Go's SSH Library Just Dropped 10 CVEs in One Day. One Is a Perfect 10.0.
CVE-2026-46595 bypasses public key authentication entirely. CVE-2026-39831 defeats hardware security keys without physical touch. Go was supposed to be the memo
June 26, 2026
Related vulnerabilities