CVE-2026-21439: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-21439 is an ASCII control character injection vulnerability in the badkeys cryptographic key scanning tool and library. In versions 0.0.15 and below, unfiltered input from scanned keys or filenames is passed directly to console output, allowing an attacker to inject ASCII control characters (e.g., vertical tabs) and ANSI escape sequences that produce misleading terminal output. The vulnerability affects DKIM key scanning (--dkim and --dkim-dns modes), SSH key scanning (--ssh-lines mode), and filename display across various modes. It was disclosed on January 3, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).

Technical details

The root cause is CWE-150 (Improper Neutralization of Escape, Meta, or Control Sequences): badkeys prints user-controlled input — such as DKIM key type values, SSH key comments, and filenames — directly to the console without sanitization. An attacker crafts a malicious key or filename containing embedded ANSI escape sequences (e.g., \e[31m) or vertical tab characters (\v) that, when rendered in a terminal, overwrite or colorize output to display false security results. The fix introduced a new internal _esc() function in utils.py using Python's repr() to backslash-escape unprintable characters before output, and separately removed the DKIM key type value from the unknown key type warning message entirely (GitHub Advisory, Commit 635a2f3, Commit de631f6).

Impact

The primary impact is integrity-related: an attacker who controls a scanned key file, DKIM record, SSH key comment, or filename can manipulate the terminal output seen by a security analyst or automated pipeline running badkeys. This could cause false negatives — making a vulnerable cryptographic key appear safe — or inject alarming fake messages to cause confusion. There is no confidentiality or availability impact; the vulnerability does not enable code execution, data exfiltration, or service disruption (GitHub Advisory, Issue #40).

Exploitability

A proof-of-concept is publicly available in the GitHub issue tracker demonstrating the injection via crafted DKIM keys, SSH key comments, and filenames with embedded ANSI escape sequences (Issue #40). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.005% (very low), reflecting the limited real-world exploitation likelihood given the narrow attack surface (GitHub Advisory).

Exploitation steps

  1. Craft a malicious DKIM key file: Create a file containing a DKIM record with an embedded ANSI escape sequence in the key type field, e.g., echo -e 'v=DKIM1;k=rsa\v\e[31mSCARY_MESSAGE\e[30m;p=AAA' > dkimkey. This embeds a vertical tab and red-colored fake message.
  2. Craft a malicious SSH key file: Create an SSH public key file with a key comment containing control characters, e.g., echo -e 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJdNlqItIkvAGtuRUJFHfUTM2RyaQaEUMAEBF9UsWSQO key\v\e[31mSCARY_MESSAGE\e[0m' > sshkeys.
  3. Craft a malicious filename: Create a file with ANSI escape sequences in its name, e.g., touch $(echo -en "RED_\e[31mLOOKS_VERY_DANGEROUS\e[0m").
  4. Trigger badkeys scanning: Run badkeys --dkim dkimkey, badkeys --ssh-lines sshkeys, or badkeys RED* on a vulnerable version (≤0.0.15).
  5. Observe misleading output: The terminal renders the injected escape sequences, displaying false or alarming messages that could cause an analyst to misinterpret the scan results — e.g., believing a vulnerable key is safe or vice versa (Issue #40).

Mitigation and workarounds

Upgrade badkeys to version 0.0.16 or later, which applies two fixes: removing the DKIM key type value from warning messages (commit de631f6) and introducing a _esc() sanitization function that backslash-escapes control characters in all console output (commit 635a2f3). Organizations unable to patch immediately should treat all badkeys output from untrusted key sources with caution and validate results through alternative methods. Restricting the sources of keys scanned by badkeys to trusted inputs is an additional interim measure (GitHub Advisory, Commit 635a2f3).

Community reactions

The vulnerability was discovered and reported by the badkeys project maintainer Hanno Böck (hannob), who also authored the fix, indicating responsible self-disclosure. The issue was rated Low severity by the maintainer and the broader community, consistent with its limited impact scope. No significant media coverage or notable external researcher commentary has been identified beyond standard vulnerability database aggregation (GitHub Advisory, Issue #40).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management