Ad

CVE-2026-4541

LOW CVSS 4.0: 2.0 EPSS 0.00%
Updated Mar 23, 2026
janmojzis
Parameter Value
CVSS 2.0 (LOW)
Type CWE-345 (Insufficient Verification of Data), CWE-347 (Improper Verification of Cryptographic Signature)
Vendor janmojzis
Public PoC No

A flaw has been found in janmojzis tinyssh up to 20250501. Impacted is an unknown function of the file tinyssh/crypto_sign_ed25519_tinyssh.c of the component Ed25519 Signature Handler. This manipulation causes improper verification of cryptographic signature.

The attack is restricted to local execution. The attack's complexity is rated as high. The exploitability is considered difficult.

The exploit has been published and may be used. Upgrading to version 20260301 is recommended to address this issue. Patch name: 9c87269607e0d7d20174df742accc49c042cff17.

Upgrading the affected component is recommended. If you want to get best quality of vulnerability data, you may have to visit VulDB.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
High
Difficult to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v4.0