CVE-2026-3706Disclosure

LOWCVSS 1.7 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is considered difficult. The actual existence of this vulnerability is currently in question. Patch name: fdec3c90a15447bd538641d85e5a3e3ac981011d. To fix this issue, it is recommended to deploy a patch. The project maintainer explains: "Signature Malleability is not exploitable in SSH protocol. (...) [A] PoC doesn't exist for SSH implementation, but rather it's against the internal API."

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-08: 3Patch / Workaround · 2026-03-08: 1Technical Details · 2026-03-08: 303-08
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3706 A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manip… https://www.cve.org/CVERecord?id=CVE-2026-3706

    Post summary

    The text announces the discovery of CVE-2026-3706 in Dropbear, specifying the impacted function and file, but contains no PoC, exploit, patch, or active attack details.

    00000106
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3706 Cryptographic Signature Verification Vulnerability in mkj Dropbear... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3706 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE‑2026‑3706 as a cryptographic signature verification issue in mkj Dropbear, linking to vulnerability details, but does not mention PoC, exploits, patches, or active exploitation.

    0000050
    4.0K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-3706: Dropbear SSH ≤2025.89 skips a critical check on Ed25519 signatures, so crafted signatures are still accepted remotely, undermining integrity and auditing. Grab the latest patch ASAP! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-3706 #Dropbear #SSH #infosec

    Post summary

    CVE-2026-3706 enables remote acceptance of forged Ed25519 signatures in Dropbear SSH up to 2025.89, and an urgent patch is available.

    0000065
    50 followersView on X

Explore more