VYPR
Critical severity9.1NVD Advisory· Published May 22, 2026· Updated Aug 18, 2026

CVE-2026-39832

CVE-2026-39832

Description

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2782

Patches

Vulnerability mechanics

References

39

News mentions

0

No linked articles in our index yet.