CVE-2025-29991: Yubico Yubikey
Low severity, CVSS 2.2. EPSS: 0.1% chance of exploitation in the next 30 days.
Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.
Affected products
- Yubico Yubikey: from 5.4.1, before 5.7.4 (fixed in 5.7.4)
Published 2025-04-03. Last modified 2026-06-17.