216.73.217.22

CVE-2026-4541

· Published 22/03/2026 09:15 · Modified 23/03/2026 14:31

Labels: CVE-2026-4541 2026-03-22CVE-2026-4541CWE-345[email protected]

Essential information

Published
22/03/2026 09:15
Modified
23/03/2026 14:31
Author
Creator
CVSS
2.0 LOW (v3) 2.0 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes improper verification of cryptographic signature. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is considered difficult. The exploit has been published and may be used. Upgrading to version 20260301 is recommended to address this issue. Patch name: 9c87269607e0d7d20174df742accc49c042cff17. Upgrading the affected component is recommended. If you want to get best quality of vulnerability data, you may have to visit VulDB.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
janmojzis / tinyssh cpe:2.3:a:janmojzis:tinyssh:<2025-05-01>:*:*:*:*:*:*:*
janmojzis / tinyssh cpe:2.3:a:janmojzis:tinyssh:20260301:*:*:*:*:*:*:*

References