Improper Neutralization Affecting badkeys package, versions [,0.0.16)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.31% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-BADKEYS-14874407
  • published13 Jan 2026
  • disclosed5 Jan 2026
  • creditHanno Böck

Introduced: 5 Jan 2026

CVE-2026-21439  (opens in a new tab)
CWE-150  (opens in a new tab)

How to fix?

Upgrade badkeys to version 0.0.16 or higher.

Overview

badkeys is a Check cryptographic keys for known weaknesses

Affected versions of this package are vulnerable to Improper Neutralization of ASCII control characters in the badkeys command-line tool. An attacker can manipulate console output to display misleading or deceptive information by injecting vertical tabs, ANSI escape sequences, or similar characters.

CVSS Base Scores

version 4.0
version 3.1