CVE-2026-86231: mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation
A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument knownhosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mwiede jschto a version that resolves this vulnerability.Fixed in 2.28.6Patch 194a2f76a5c0f1c3f778565be3fd66bcafc42d23
Event History
Frequently Asked Questions
Does exploitation require authentication or local access?
No privileges or user interaction are required. The issue can be exploited remotely over the network, although exploitation is rated high complexity and described as difficult.
What is the expected security impact?
The reported impact is limited to integrity. No confidentiality or availability impact is indicated by the supplied severity vector.
What remediation is available?
Upgrade mwiede jsch to version 2.28.6. The referenced fix is commit 194a2f76a5c0f1c3f778565be3fd66bcafc42d23.