
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21439 is an ASCII control character injection vulnerability in the badkeys cryptographic key scanning tool and library. In versions 0.0.15 and below, unfiltered input from scanned keys or filenames is passed directly to console output, allowing an attacker to inject ASCII control characters (e.g., vertical tabs) and ANSI escape sequences that produce misleading terminal output. The vulnerability affects DKIM key scanning (--dkim and --dkim-dns modes), SSH key scanning (--ssh-lines mode), and filename display across various modes. It was disclosed on January 3, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).
The root cause is CWE-150 (Improper Neutralization of Escape, Meta, or Control Sequences): badkeys prints user-controlled input — such as DKIM key type values, SSH key comments, and filenames — directly to the console without sanitization. An attacker crafts a malicious key or filename containing embedded ANSI escape sequences (e.g., \e[31m) or vertical tab characters (\v) that, when rendered in a terminal, overwrite or colorize output to display false security results. The fix introduced a new internal _esc() function in utils.py using Python's repr() to backslash-escape unprintable characters before output, and separately removed the DKIM key type value from the unknown key type warning message entirely (GitHub Advisory, Commit 635a2f3, Commit de631f6).
The primary impact is integrity-related: an attacker who controls a scanned key file, DKIM record, SSH key comment, or filename can manipulate the terminal output seen by a security analyst or automated pipeline running badkeys. This could cause false negatives — making a vulnerable cryptographic key appear safe — or inject alarming fake messages to cause confusion. There is no confidentiality or availability impact; the vulnerability does not enable code execution, data exfiltration, or service disruption (GitHub Advisory, Issue #40).
A proof-of-concept is publicly available in the GitHub issue tracker demonstrating the injection via crafted DKIM keys, SSH key comments, and filenames with embedded ANSI escape sequences (Issue #40). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.005% (very low), reflecting the limited real-world exploitation likelihood given the narrow attack surface (GitHub Advisory).
echo -e 'v=DKIM1;k=rsa\v\e[31mSCARY_MESSAGE\e[30m;p=AAA' > dkimkey. This embeds a vertical tab and red-colored fake message.echo -e 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJdNlqItIkvAGtuRUJFHfUTM2RyaQaEUMAEBF9UsWSQO key\v\e[31mSCARY_MESSAGE\e[0m' > sshkeys.touch $(echo -en "RED_\e[31mLOOKS_VERY_DANGEROUS\e[0m").badkeys --dkim dkimkey, badkeys --ssh-lines sshkeys, or badkeys RED* on a vulnerable version (≤0.0.15).Upgrade badkeys to version 0.0.16 or later, which applies two fixes: removing the DKIM key type value from warning messages (commit de631f6) and introducing a _esc() sanitization function that backslash-escapes control characters in all console output (commit 635a2f3). Organizations unable to patch immediately should treat all badkeys output from untrusted key sources with caution and validate results through alternative methods. Restricting the sources of keys scanned by badkeys to trusted inputs is an additional interim measure (GitHub Advisory, Commit 635a2f3).
The vulnerability was discovered and reported by the badkeys project maintainer Hanno Böck (hannob), who also authored the fix, indicating responsible self-disclosure. The issue was rated Low severity by the maintainer and the broader community, consistent with its limited impact scope. No significant media coverage or notable external researcher commentary has been identified beyond standard vulnerability database aggregation (GitHub Advisory, Issue #40).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."