Skip to main content
EPSS 7.3%top 6.0%

CVE-2026-42508: CWE-295: Improper Certificate Validation in golang.org/x/crypto golang.org/x/crypto/ssh/knownhosts

0
Critical
VulnerabilityCVE-2026-42508cvecve-2026-42508cwe-295
Published: 05/22/2026 (05/22/2026, 02:31:27 UTC)
Source: CVE Database V5
Vendor/Project: golang.org/x/crypto
Product: golang.org/x/crypto/ssh/knownhosts

Description

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

CVSS v3.1

Score 9.1critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected software

golang.org/x/crypto

golang.org/x/crypto/ssh/knownhosts

Affected versions
>=0 <0.52.0
golang.org/x/crypto/ssh/knownhosts
pkg:golang/golang.org/x/crypto/ssh/knownhosts
Affected versions
=0
golang.org/x/crypto/ssh/knownhosts
pkg:golang/golang.org/x/crypto/ssh/knownhosts
Affected versions
>=0 <0.52.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 13:20:31 UTC

Technical Analysis

The vulnerability in golang.org/x/crypto/ssh/knownhosts arises from improper validation of the revocation status of a SignatureKey belonging to a Certificate Authority. Previously, the system did not check if the SignatureKey was revoked, allowing an attacker to bypass security checks by presenting a revoked key. This could lead to acceptance of malicious or spoofed keys, enabling unauthorized access or impersonation of legitimate hosts. The issue is classified as CWE-295 (Improper Certificate Validation) and has a critical CVSS score of 9.1. Red Hat's advisory details the impact and references multiple related CVEs and fixes in the golang.org/x/crypto package, including this one. While fixes are in progress, the advisory does not explicitly confirm patch availability for all affected products, recommending users monitor vendor updates.

Potential Impact

The vulnerability allows a remote attacker to bypass security checks by presenting a revoked SignatureKey from a Certificate Authority, which the system incorrectly accepts as valid. This can lead to unauthorized access or spoofing of legitimate entities, compromising confidentiality and integrity of communications. The CVSS score of 9.1 reflects critical impact with no privileges or user interaction required. There are no known exploits in the wild at this time. The flaw affects systems using the golang.org/x/crypto/ssh/knownhosts package that do not properly validate key revocation status.

Mitigation Recommendations

Red Hat has issued advisories acknowledging the vulnerability and is working on fixes. Users should monitor the Red Hat advisory pages and apply updates once available. The advisory does not explicitly state that a patch is currently available, so patch status is not yet confirmed. Until a fix is applied, users should consider mitigating exposure by restricting access to affected systems and monitoring for suspicious activity related to SSH key usage. Consult the vendor advisory for the latest remediation guidance and update instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Go
Date Reserved
2026-04-28T00:21:12.792Z
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-42508","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23262","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:23264","vendor":"Red Hat"}]

Threat ID: 6a0fcdabe1370fbb487d502f

Added to database: 05/22/2026, 03:29:47 UTC

Last enriched: 08/17/2026, 13:20:31 UTC

Last updated: 09/14/2026, 22:11:26 UTC

Views: 136

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses