CVE-2026-86231 | mwiede jsch up to 2.28.5 KnownHosts.java getRevokedKeys known_hosts improper check for certificate revocation (Issue 1091)

SecurityVulns

A vulnerability identified as problematic has been detected in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation.

This vulnerability is reported as CVE-2026-86231. The attack is possible to be carried out remotely. Moreover, an exploit is present.

You should upgrade the affected component.VulDB Recent EntriesRead More