Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 06 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component. | |
| Title | mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation | |
| First Time appeared |
Mwiede
Mwiede jsch |
|
| Weaknesses | CWE-298 CWE-299 |
|
| CPEs | cpe:2.3:a:mwiede:jsch:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mwiede
Mwiede jsch |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-06T22:45:12.262Z
Reserved: 2026-09-06T08:04:47.571Z
Link: CVE-2026-86231
No data.
Status : Received
Published: 2026-09-06T23:17:39.157
Modified: 2026-09-06T23:17:39.157
Link: CVE-2026-86231
No data.
OpenCVE Enrichment
No data.