CVE-2026-42508
golang.org/x/crypto golang.org/x/crypto/ssh/knownhosts, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
- CVSS
- 9.1
- EPSS
- 0.57% 43.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.22