CVE-2023-39908: Yubico Yubihsm 2 SDK

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

Affected products

  • Yubico Yubihsm 2 SDK: before 2023.08 (fixed in 2023.08)

Published 2023-08-14. Last modified 2026-06-17.