← Back

CVE-2026-39833

nvd nist
Published: May 22, 2026Modified: Jul 23, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.

Affected (1)

Products: Golang: Crypto
1 product
Crypto
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.52.0

References (5)

Source: security@golang.org
Issue Tracking
Source: security@golang.org
Issue Tracking
Source: security@golang.org
Issue Tracking
Source: security@golang.org
Mailing List
Source: security@golang.org
Vendor Advisory

Timeline

No history available yet.