CyberShieldTips
Best Of
How-To Guides
Password Managers
Privacy Tools
Threat Analysis
VPN Reviews
📚 Resources
☰
Home
›
CVE Database
›
Putty
›
CVE-2026-48852
CVE-2026-48852
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
low
3.7
CVSS 3.1
Published:
May 25, 2026
Modified:
May 27, 2026
Vendor:
Putty
Product:
Putty
Description
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
References
https://lists.tartarus.org/pipermail/putty-announce/2026/000042.html
https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/ecdsa-remotely-triggerable-assertion.html
Related CVEs
CVE-2026-48850
low · 3.7
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
CVE-2026-48851
low · 3.1
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
CVE-2026-4115
low · 3.7
A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results