Home

Description

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes improper verification of cryptographic signature. The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is considered difficult. The exploit has been published and may be used. Upgrading to version 20260301 is recommended to address this issue. Patch name: 9c87269607e0d7d20174df742accc49c042cff17. Upgrading the affected component is recommended.

PUBLISHED Reserved 2026-03-21 | Published 2026-03-22 | Updated 2026-04-18 | Assigner VulDB




LOW: 2.0CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
LOW: 2.5CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
LOW: 2.5CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
1.0AV:L/AC:H/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C

Problem types

Improper Verification of Cryptographic Signature

Insufficient Verification of Data Authenticity

Product status

20250501
affected

20260301
unaffected

Timeline

2026-03-01:Countermeasure disclosed
2026-03-21:Advisory disclosed
2026-03-21:VulDB entry created
2026-03-23:VulDB entry last update

Credits

pythok (VulDB User) reporter

References

vuldb.com/vuln/352358 (VDB-352358 | janmojzis tinyssh Ed25519 Signature crypto_sign_ed25519_tinyssh.c signature verification) vdb-entry

vuldb.com/vuln/352358/cti (VDB-352358 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/submit/774687 (Submit #774687 | GitHub tinyssh 20250501 Cryptographic Issues) third-party-advisory

github.com/janmojzis/tinyssh/issues/101 issue-tracking

github.com/janmojzis/tinyssh/pull/102 issue-tracking patch

github.com/janmojzis/tinyssh/issues/101 exploit issue-tracking

github.com/...ommit/9c87269607e0d7d20174df742accc49c042cff17 patch

github.com/janmojzis/tinyssh/releases/tag/20260301 patch

github.com/janmojzis/tinyssh/ product

cve.org (CVE-2026-4541)

nvd.nist.gov (CVE-2026-4541)

Download JSON