CVE-2026-21439

MEDIUM

badkeys <0.0.15 - Info Disclosure

Title source: llm
STIX 2.1

Description

badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and below, an attacker may inject content with ASCII control characters like vertical tabs, ANSI escape sequences, etc., that can create misleading output of the badkeys command-line tool. This impacts scanning DKIM keys (both --dkim and --dkim-dns), SSH keys (--ssh-lines mode), and filenames in various modes. This issue is fixed in version 0.0.16.

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 2.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-150
Status published
Products (2)
badkeys/badkeys < 0.0.16
pypi/badkeys 0 - 0.0.16PyPI
Published Jan 06, 2026
Tracked Since Feb 18, 2026