CVE-2026-4541Disclosure

LOWCVSS 1.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes improper verification of cryptographic signature. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is considered difficult. The exploit has been published and may be used. Upgrading to version 20260301 is recommended to address this issue. Patch name: 9c87269607e0d7d20174df742accc49c042cff17. Upgrading the affected component is recommended.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-22); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-22: 3Mentions · 2026-03-23: 2Technical Details · 2026-03-22: 3Technical Details · 2026-03-23: 203-2203-23
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-223
Disclosure2General1
2026-03-232
Disclosure2
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4541 Ed25519 Signature Verification Vulnerability in TinySSH Before 20260301 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4541

    Post summary

    The brief note identifies CVE-2026-4541 as an Ed25519 signature verification flaw in TinySSH but offers no further technical details, PoC, exploit, or patch information.

    0000140
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4541 A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Si… https://www.cve.org/CVERecord?id=CVE-2026-4541 ----- Traducción: CVE-2026-4541 Se … http://infoflow.cloud`

    Post summary

    An announcement identifies CVE-2026-4541 in TinySSH, detailing affected files but providing no exploit information or patches.

    0000013
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4541 A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Si… https://www.cve.org/CVERecord?id=CVE-2026-4541

    Post summary

    A new vulnerability, CVE‑2026‑4541, has been disclosed in TinySSH’s Ed25519 component, with limited technical details available but no exploits or patches reported.

    00000116
    56.8K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4541 📊 Severity: 2.5 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4541 #CVE-2026-4541 #CVE #Low  #CyberSecurity #InfoSec https://t.co/T6Gx35Rivt

    Post summary

    The tweet announces CVE-2026-4541 as a low‑severity vulnerability affecting unspecified products, linking only to the NVD page for more information.

    0000019
    111 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4541 - janmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verification Intel Report: https://ift.tt/pwDcyok

    Post summary

    A newly disclosed CVE-2026-4541 involves a critique on the Ed25519 signature verification in janmojzis tinyssh, with a reference to an Intel report but no PoC, exploit, or patch details provided.

    0000022
    292 followersView on X

Explore more