CVE detail
CVE-2026-3706
A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is considered difficult. The actual existence of this vulnerability is currently in question. Patch name: fdec3c90a15447bd538641d85e5a3e3ac981011d. To fix this issue, it is recommended to deploy a patch. The project maintainer explains: "Signature Malleability is not exploitable in SSH protocol. (...) [A] PoC doesn't exist for SSH implementation, but rather it's against the internal API."
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/?submit.765933vuldb.com
No excerpt available.
Exploitvuldb.comMar 8, 2026, 5:16 AM - https://vuldb.com/?id.349652vuldb.com
No excerpt available.
Exploitvuldb.comMar 8, 2026, 5:16 AM - https://vuldb.com/?ctiid.349652vuldb.com
No excerpt available.
Exploitvuldb.comMar 8, 2026, 5:16 AM No excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AM- https://github.com/mkj/dropbear/pull/407github.com
No excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AM No excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AMNo excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AM- https://github.com/mkj/dropbear/github.com
No excerpt available.
Exploitgithub.comMar 8, 2026, 5:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-47304CVSS 8.1 · High
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-54783CVSS 7.4 · High
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature veri…
- CVE-2026-54774CVSS 7.4 · High
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when…
- CVE-2026-7689CVSS 2.9 · Low
A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verifyHash in the library htdocs/core/lib/security.lib.php of the…
- CVE-2026-6986CVSS 2.9 · Low
A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Au…
- CVE-2026-4115CVSS 2.9 · Low
A vulnerability was detected in PuTTY 0.83. Affected is the function eddsa_verify of the file crypto/ecc-ssh.c of the component Ed25519 Signature Handler. The manipulation results…