CVE-2026-48852 Details
Description
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
An assertion failure vulnerability has been identified in PuTTY versions 0.71 prior to 0.84, during the ECDSA signature verification process. This vulnerability allows a malicious server or a man-in-the-middle attacker to cause PuTTY to crash by sending carefully crafted host keys and signatures during the initial SSH key exchange. The issue arises from an improper assertion in the elliptic curve arithmetic, which incorrectly treats the addition of two points with the same y-coordinate as an error, leading to a denial-of-service condition by causing the application to crash.
Users can upgrade to PuTTY version 0.84 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.tartarus.org/pipermail/putty-announce/2026/000042.html | [email protected] | Release Notes |
| https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/ecdsa-remotely-triggerable-assertion.html | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| putty putty | >= 0.71, < 0.84 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | Initial Analysis | [email protected] |
| May 25, 2026 | New CVE Received | [email protected] |