No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 06 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component. | |
| Title | mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation | |
| First Time appeared |
Mwiede
Mwiede jsch |
|
| Weaknesses | CWE-298 CWE-299 |
|
| CPEs | cpe:2.3:a:mwiede:jsch:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mwiede
Mwiede jsch |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-06T22:45:12.262Z
Reserved: 2026-09-06T08:04:47.571Z
Link: CVE-2026-86231
No data.
Status : Received
Published: 2026-09-06T23:17:39.157
Modified: 2026-09-06T23:17:39.157
Link: CVE-2026-86231
No data.
OpenCVE Enrichment
No data.