badkeys vulnerable to ASCII control character injection on console via malformed input
Description
Published to the GitHub Advisory Database
Jan 5, 2026
Reviewed
Jan 5, 2026
Published by the National Vulnerability Database
Jan 6, 2026
Last updated
Jan 6, 2026
Impact
An attacker may inject content with ASCII control characters like vertical tabs, ANSI escape sequences, etc., that can create misleading output of the
badkeyscommand-line tool. This impacts scanning DKIM keys (both--dkimand--dkim-dns), SSH keys (--ssh-linesmode), and filenames in various modes.Patches
This has been fixed with the following commits:
badkeys/badkeys@de631f6
badkeys/badkeys@635a2f3
All users should upgrade
badkeysto version 0.0.16.Resources
badkeys/badkeys#40
References