Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wjpc-4f29-83h3 | badkeys vulnerable to ASCII control character injection on console via malformed input |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and below, an attacker may inject content with ASCII control characters like vertical tabs, ANSI escape sequences, etc., that can create misleading output of the badkeys command-line tool. This impacts scanning DKIM keys (both --dkim and --dkim-dns), SSH keys (--ssh-lines mode), and filenames in various modes. This issue is fixed in version 0.0.16. | |
| Title | badkeys vulnerable to ASCII control character injection on console via malformed input | |
| Weaknesses | CWE-150 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-06T19:01:48.962Z
Reserved: 2025-12-29T03:00:29.275Z
Link: CVE-2026-21439
Updated: 2026-01-06T14:24:31.956Z
Status : Received
Published: 2026-01-06T00:15:49.027
Modified: 2026-01-06T19:16:07.820
Link: CVE-2026-21439
No data.
OpenCVE Enrichment
No data.
Github GHSA