Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 16 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unintended DLL Search Path in Yubico Authentication Libraries | |
| First Time appeared |
Yubico
Yubico libfido2 Yubico python-fido2 Yubico yubikey-manager |
|
| Vendors & Products |
Yubico
Yubico libfido2 Yubico python-fido2 Yubico yubikey-manager |
Wed, 15 Apr 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path. | |
| Weaknesses | CWE-426 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-16T13:18:13.069Z
Reserved: 2026-04-15T23:11:52.721Z
Link: CVE-2026-40947
Updated: 2026-04-16T13:18:09.606Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-04-16T09:15:30Z
Weaknesses