---
id: CVE-2026-42508
title: >-
  Previously, a revoked 'SignatureKey' belonging to a CA was not correctly
  checked for revocation
summary: >-
  Previously, a revoked 'SignatureKey' belonging to a CA was not correctly
  checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked
  for @revoked.
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-295
vendor: golang
product: crypto
affected:
  - crypto < 0.52.0
patched:
  - crypto 0.52.0
published: '2026-05-22'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T12:17:45.777'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42508'
references:
  - url: 'https://go.dev/cl/781220'
    label: security@golang.org
  - url: 'https://go.dev/issue/79568'
    label: security@golang.org
  - url: 'https://groups.google.com/g/golang-announce/c/a082jnz-LvI'
    label: security@golang.org
  - url: 'https://pkg.go.dev/vuln/GO-2026-5021'
    label: security@golang.org
  - url: 'https://access.redhat.com/errata/RHSA-2026:23262'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:23264'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26546'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26547'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:35833'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36648'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36651'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36796'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36797'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36808'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37072'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37123'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37387'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:40118'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:40262'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:40945'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41019'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41031'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41036'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41064'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41066'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42146'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42796'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43052'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43692'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:46885'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:47735'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:47737'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:49944'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:51033'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:51288'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:52857'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:52910'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:54400'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:57194'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:59467'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:61314'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:66022'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:66521'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:67450'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42508'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2480688'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-42508'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42508'
  - url: 'https://github.com/advisories/GHSA-5cgq-3rg8-m6cv'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70870'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - ghsa
  - go
  - osv
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-05-22T18:43:40.584666Z'
epss: 0.00654
epssPercentile: 0.49175
ecosystem: go
scores:
  nvd: 9.1
  adp: 9.1
  vendor: 7.4
ingestedAt: '2026-06-26T16:43:14.192Z'
aliases:
  - GO-2026-5021
  - GHSA-5cgq-3rg8-m6cv
---

## Overview

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

## Affected

- `crypto < 0.52.0`

## Remediation

Upgrade past the affected range:

- `crypto 0.52.0`

## Package advisory (CVE-2026-42508)

Affected packages:

- `golang.org/x/crypto/ssh/knownhosts < 0.52.0`

Patched in:

- `golang.org/x/crypto/ssh/knownhosts 0.52.0`

Source: https://github.com/advisories/GHSA-5cgq-3rg8-m6cv

## Vendor advisories

- **RHSA-2026:41019** · Red Hat · fixed in: RHEM 1.1 for RHEL 10, RHEM 1.1 for RHEL 9 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41019)
- **RHSA-2026:36796** · Red Hat · fixed in: RHEM 1.0 for RHEL 9 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36796)
- **RHSA-2026:37072** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37072)
- **RHSA-2026:35833** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:35833)
- **RHSA-2026:51288** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51288)
- **RHSA-2026:49944** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:49944)
- **RHSA-2026:37123** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37123)
- **RHSA-2026:61314** · Red Hat · fixed in: Cluster Observability Operator 1.5.0 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61314)
- **RHSA-2026:36808** · Red Hat · fixed in: DevWorkspace Operator 0.42 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36808)
- **RHSA-2026:66521** · Red Hat · fixed in: Logging Subsystem for Red Hat OpenShift 6.6 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66521)
- **RHSA-2026:51033** · Red Hat · fixed in: OpenShift API for Data Protection 1.3 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51033)
- **Red Hat VEX** · Important · affected: cert-manager Operator for Red Hat OpenShift, External Secrets Operator for Red Hat OpenShift, OpenShift Pipelines, OpenShift Serverless, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, … · no fix planned: External Secrets Operator for Red Hat OpenShift, Red Hat OpenShift Container Platform 4, cert-manager Operator for Red Hat OpenShift, OpenShift Pipelines, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json)
- **RHSA-2026:59467** · Red Hat · fixed in: OpenShift API for Data Protection 1.4 · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59467)
- **RHSA-2026:67450** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67450)
- **RHSA-2026:70870** · Red Hat · fixed in: Logging Subsystem for Red Hat OpenShift 6.5 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70870)
