CVE-2026-40947

EUVD-2026-23135
Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.9 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.92%
Debian logo
Debian Releases
Debian Product
Codename
libfido2
bookworm
1.12.0-2
fixed
bullseye
1.6.0-2
fixed
forky
1.17.0-2
fixed
sid
1.17.0-2
fixed
trixie
1.15.0-1
fixed
python-fido2
bookworm
0.9.1-1
fixed
bullseye
0.9.1-1
fixed
forky
2.2.1-2
fixed
sid
2.2.1-2
fixed
trixie
1.2.0-2
fixed
yubikey-manager
bookworm
4.0.9-1
fixed
bullseye
4.0.0~a1-4
fixed
forky
5.9.2-1
fixed
sid
5.9.2-1
fixed
trixie
5.6.1+repack1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libfido2
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
python-fido2
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
yubikey-manager
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected