Junglewise Threat Intelligence

CVE-2026-48852: PuTTY assertion failure in ECDSA signature verification

CVE-2026-48852 · Severity: low · CVSS 3.7 · Published 2026-05-25

Technologies: Putty. Vendors: Putty.

Executive brief

PuTTY, a popular tool for connecting to remote servers, is vulnerable to a crash during the initial connection phase. A malicious server or an attacker positioned between the user and the server can send specially crafted security keys that cause the application to shut down unexpectedly. While this does not allow an attacker to steal data or take over a system, it can result in the loss of terminal scrollback history if the user was reusing an existing window.

Technical details

An assertion failure (CWE-617) exists in PuTTY's elliptic curve arithmetic logic when processing NIST Weierstrass curves (P256, P384, and P521). The vulnerability is triggered when the application attempts to add two elliptic curve points with identical y-coordinates during host key signature verification. An unauthenticated remote attacker or Man-in-the-Middle (MITM) can trigger this crash by providing a malicious host key and signature during the initial SSH key exchange. Because verification occurs before the host key is validated against the local cache, the crash happens before any host key warnings are displayed. The issue is resolved in version 0.84.

Affected products

  • PuTTY PuTTY 0.71 to 0.83

Timeline

  • 2026-05-22: patched: Fixed in version 0.84
  • 2026-05-25: disclosed: CVE published

References

Related threats