CVE-2026-40947

NameCVE-2026-40947
DescriptionYubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libfido2 (PTS)bullseye1.6.0-2fixed
bookworm1.12.0-2fixed
trixie1.15.0-1fixed
forky1.16.0-2fixed
sid1.17.0-1fixed
python-fido2 (PTS)bookworm, bullseye0.9.1-1fixed
trixie1.2.0-2fixed
forky2.0.0-1fixed
sid2.2.0-2fixed
yubikey-manager (PTS)bullseye4.0.0~a1-4fixed
bookworm4.0.9-1fixed
trixie5.6.1+repack1-1fixed
forky5.8.0-4fixed
sid5.9.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libfido2source(unstable)(not affected)
python-fido2source(unstable)(not affected)
yubikey-managersource(unstable)(not affected)

Notes

- libfido2 <not-affected> (Only affects libfido2 on Windows)
- python-fido2 <not-affected> (Only affects python-fido2 on Windows)
- yubikey-manager <not-affected> (Only affects python-fido2 on Windows)
https://www.yubico.com/support/security-advisories/ysa-2026-01/

Search for package or bug name: Reporting problems