CVE-2026-39833Active Exploitation(golang / crypto)

LOWCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for golang crypto systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.

3.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crypto

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
crypto

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-22: 1Mentions · 2026-08-06: 1Active Exploitation · 2026-05-22: 1Technical Details · 2026-08-06: 105-2208-06
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-221
Active Exploitation1
2026-08-061
General1
Full discourse2 posts
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    Patching windows matter. CVE-2026-39833 is a good reminder why. http://golang.org/x/crypto/ssh/agent doesn't enforce invoking key constraints The best defense is the one you set up before you needed it.

    Post summary

    CVE‑2026‑39833 is highlighted as a vulnerability in golang’s SSH agent that fails to enforce key constraints, with a reminder that timely patching is essential.

    0000049
    357 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting x-crypto (CVE-2026-39833) https://vuldb.com/vuln/365128/cti

    Post summary

    The post reports elevated activity against CVE‑2026‑39833, indicating that it is likely being exploited in the wild, though no PoC, exploit code, or mitigation details are provided.

    0000063
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgolangcrypto-go-

Explore more