Insufficient Verification of Data Authenticity Affecting dropbear package, versions <2026.90-1


Severity

Recommended
0.0
low
0
10

Based on Debian security rating.

Threat Intelligence

EPSS
0.16% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-DROPBEAR-15440613
  • published9 Mar 2026
  • disclosed8 Mar 2026

Introduced: 8 Mar 2026

CVE-2026-3706  (opens in a new tab)
CWE-345  (opens in a new tab)
CWE-347  (opens in a new tab)

How to fix?

Upgrade Debian:unstable dropbear to version 2026.90-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream dropbear package and not the dropbear package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is considered difficult. The actual existence of this vulnerability is currently in question. Patch name: fdec3c90a15447bd538641d85e5a3e3ac981011d. To fix this issue, it is recommended to deploy a patch. The project maintainer explains: "Signature Malleability is not exploitable in SSH protocol. (...) [A] PoC doesn't exist for SSH implementation, but rather it's against the internal API."

CVSS Base Scores

version 3.1