CVE-2019-9578: Yubico LIBU2F-Host
High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
Affected products
- Yubico LIBU2F-Host: before 1.1.8 (fixed in 1.1.8)
Published 2019-03-05. Last modified 2026-06-17.