The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade nerdctl-debuginfoUpgrade dockerUpgrade nerdctlUpgrade containerd-stressUpgrade runfinch-finchUpgrade amazon-cloudwatch-agentUpgrade docker-debuginfoUpgrade containerd-debuginfoUpgrade rclone-debuginfoUpgrade rcloneUpgrade containerd | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade docker-debuginfoUpgrade docker-debugsourceUpgrade rclone-debugsourceUpgrade amazon-cloudwatch-agentUpgrade runfinch-finchUpgrade nerdctlUpgrade containerd-stressUpgrade containerdUpgrade containerd-stress-debuginfoUpgrade rcloneUpgrade containerd-debugsourceUpgrade dockerUpgrade containerd-debuginfoUpgrade rclone-debuginfo | Jun 9, 2026 | May 22, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 22, 2026 |
| Ubuntu | — | Upgrade golang-golang-x-crypto-dev (Ubuntu Pro)Upgrade golang-go.crypto-dev (Ubuntu Pro)Upgrade lxd (Ubuntu Pro) | Jun 18, 2026 | Jun 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub