CVE-2026-42508: CWE-295: Improper Certificate Validation in golang.org/x/crypto golang.org/x/crypto/ssh/knownhosts
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
AI Analysis
Technical Summary
The vulnerability in golang.org/x/crypto/ssh/knownhosts arises from improper validation of the revocation status of a SignatureKey belonging to a Certificate Authority. Previously, the system did not check if the SignatureKey was revoked, allowing an attacker to bypass security checks by presenting a revoked key. This could lead to acceptance of malicious or spoofed keys, enabling unauthorized access or impersonation of legitimate hosts. The issue is classified as CWE-295 (Improper Certificate Validation) and has a critical CVSS score of 9.1. Red Hat's advisory details the impact and references multiple related CVEs and fixes in the golang.org/x/crypto package, including this one. While fixes are in progress, the advisory does not explicitly confirm patch availability for all affected products, recommending users monitor vendor updates.
Potential Impact
The vulnerability allows a remote attacker to bypass security checks by presenting a revoked SignatureKey from a Certificate Authority, which the system incorrectly accepts as valid. This can lead to unauthorized access or spoofing of legitimate entities, compromising confidentiality and integrity of communications. The CVSS score of 9.1 reflects critical impact with no privileges or user interaction required. There are no known exploits in the wild at this time. The flaw affects systems using the golang.org/x/crypto/ssh/knownhosts package that do not properly validate key revocation status.
Mitigation Recommendations
Red Hat has issued advisories acknowledging the vulnerability and is working on fixes. Users should monitor the Red Hat advisory pages and apply updates once available. The advisory does not explicitly state that a patch is currently available, so patch status is not yet confirmed. Until a fix is applied, users should consider mitigating exposure by restricting access to affected systems and monitoring for suspicious activity related to SSH key usage. Consult the vendor advisory for the latest remediation guidance and update instructions.
CVE-2026-42508: CWE-295: Improper Certificate Validation in golang.org/x/crypto golang.org/x/crypto/ssh/knownhosts
Description
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVSS v3.1
Score 9.1critical
Affected software
golang.org/x/crypto
golang.org/x/crypto/ssh/knownhosts
pkg:golang/golang.org/x/crypto/ssh/knownhostspkg:golang/golang.org/x/crypto/ssh/knownhostsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in golang.org/x/crypto/ssh/knownhosts arises from improper validation of the revocation status of a SignatureKey belonging to a Certificate Authority. Previously, the system did not check if the SignatureKey was revoked, allowing an attacker to bypass security checks by presenting a revoked key. This could lead to acceptance of malicious or spoofed keys, enabling unauthorized access or impersonation of legitimate hosts. The issue is classified as CWE-295 (Improper Certificate Validation) and has a critical CVSS score of 9.1. Red Hat's advisory details the impact and references multiple related CVEs and fixes in the golang.org/x/crypto package, including this one. While fixes are in progress, the advisory does not explicitly confirm patch availability for all affected products, recommending users monitor vendor updates.
Potential Impact
The vulnerability allows a remote attacker to bypass security checks by presenting a revoked SignatureKey from a Certificate Authority, which the system incorrectly accepts as valid. This can lead to unauthorized access or spoofing of legitimate entities, compromising confidentiality and integrity of communications. The CVSS score of 9.1 reflects critical impact with no privileges or user interaction required. There are no known exploits in the wild at this time. The flaw affects systems using the golang.org/x/crypto/ssh/knownhosts package that do not properly validate key revocation status.
Mitigation Recommendations
Red Hat has issued advisories acknowledging the vulnerability and is working on fixes. Users should monitor the Red Hat advisory pages and apply updates once available. The advisory does not explicitly state that a patch is currently available, so patch status is not yet confirmed. Until a fix is applied, users should consider mitigating exposure by restricting access to affected systems and monitoring for suspicious activity related to SSH key usage. Consult the vendor advisory for the latest remediation guidance and update instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Go
- Date Reserved
- 2026-04-28T00:21:12.792Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-42508","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23262","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23264","vendor":"Red Hat"}]
Threat ID: 6a0fcdabe1370fbb487d502f
Added to database: 05/22/2026, 03:29:47 UTC
Last enriched: 08/17/2026, 13:20:31 UTC
Last updated: 09/14/2026, 22:11:26 UTC
Views: 136
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.