Skip to content
Vulnerability intelligence

CVE-2026-39831 — Security Advisory

CVE-2026-39831 (CVSS 9.1): the Verify() method for FIDO/U2F key types in golang.org/x/crypto/ssh never checked the User Presence flag. An attacker with agent access could authenticate silently, defeating the one guarantee hardware keys exist to enforce.

CVSS 9.1 2026