CVE-2026-91166

medium

Description

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead passes ssh_options.host and ssh_options.port for the final target to KnownHosts::trust. In Prompt and AutoAccept modes, a jump host key can therefore be stored for the target address. A machine later presenting the jump host key at the target address can be accepted as the target, allowing interception of user traffic and a newly issued certificate when certificate authentication is used. The native SSH path is unaffected because it tracks each hop separately. This issue is fixed in version 0.27.6.

References

https://github.com/warp-tech/warpgate/security/advisories/GHSA-w9jj-vpw3-5r8f

https://github.com/warp-tech/warpgate/releases/tag/v0.27.6

https://github.com/warp-tech/warpgate/commit/fb66ff74f979c22054f4d348cc0d9065cc67e5d3

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-84064

Details

Source: Mitre, NVD

Published: 2026-09-21

Updated: 2026-09-24

Risk Information

CVSS v2

Base Score: 6.2

Vector: CVSS2#AV:N/AC:H/Au:M/C:C/I:C/A:N

Severity: Medium

CVSS v3

Base Score: 5.7

Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

Severity: Medium

EPSS

EPSS: 0.00218