The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade nerdctl-debuginfoUpgrade nerdctlUpgrade containerd-stressUpgrade dockerUpgrade rcloneUpgrade containerdUpgrade rclone-debuginfoUpgrade runfinch-finchUpgrade docker-debuginfoUpgrade amazon-cloudwatch-agentUpgrade containerd-debuginfo | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade rclone-debuginfoUpgrade dockerUpgrade containerdUpgrade containerd-debuginfoUpgrade containerd-debugsourceUpgrade containerd-stressUpgrade rcloneUpgrade containerd-stress-debuginfoUpgrade amazon-cloudwatch-agentUpgrade docker-debugsourceUpgrade nerdctlUpgrade rclone-debugsourceUpgrade runfinch-finchUpgrade docker-debuginfo | Jun 9, 2026 | May 22, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 22, 2026 |
| Ubuntu | — | Upgrade golang-go.crypto-dev (Ubuntu Pro)Upgrade golang-golang-x-crypto-dev (Ubuntu Pro)Upgrade lxd (Ubuntu Pro) | Jun 18, 2026 | Jun 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub