QSearchQSearch

CVE-2026-4115

3.7 LOW

A vulnerability was detected in PuTTY 0.83

Published: 2026-03-22 · Last updated: 2026-04-30

Severity and scoring

CVSS
3.7 LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE
CWE-345, CWE-347

Affected products

VendorProduct
puttyputty

Description

A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results in improper verification of cryptographic signature. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The real existence of this vulnerability is still doubted at the moment. The patch is identified as af996b5ec27ab79bae3882071b9d6acf16044549. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a patch for the affected product. However, at the moment there is no proof that this flaw might have any real-world impact.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-48852 PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification (3.7 LOW)
  • CVE-2026-48851 PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between pr... (3.1 LOW)
  • CVE-2026-48850 PuTTY 0.72 before 0.84 has a double free in RSA KEX (3.7 LOW)

Same CWE

  • CVE-2026-46654 Plonky3 is a toolkit for polynomial IOPs (PIOPs)
  • CVE-2026-42462 Fedify is a TypeScript library for building federated server apps powered by ActivityPub (7.0 HIGH)
  • CVE-2026-48096 OpenFGA is an authorization/permission engine built for developers (5.0 MEDIUM)
  • CVE-2026-52754 Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a ... (8.8 HIGH)
  • CVE-2026-46539 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm (5.9 MEDIUM)