CVE-2026-86231 affects JSch, a Java library implementing the SSH2 protocol used to embed SSH client functionality directly into Java applications — this record specifically concerns the actively maintained mwiede/jsch fork, which took over development after the original project’s maintenance slowed.
What the vulnerability does
Per the vulnerability record, the flaw is in the getRevokedKeys function of KnownHosts.java. Manipulating the known_hosts argument results in an improper check for certificate (key) revocation — meaning JSch’s mechanism for recognizing a host key that should be treated as revoked can be bypassed under certain conditions. Affected versions run through 2.28.5.
The record explicitly flags this as high attack complexity and states the exploitability is “difficult” — this isn’t a trivially weaponizable bug. CVSS base score is 3.7 (low), consistent with a bypass that requires specific conditions to be met rather than a straightforward remote trigger.
Fix and affected versions
Fixed in JSch 2.28.6, per the project’s own patch (commit 194a2f76a5c0f1c3f778565be3fd66bcafc42d23). Applications embedding JSch for SSH connectivity should upgrade to 2.28.6 or later.
Confidence
This traces to the JSch project’s own repository, with a named function, file, and patch commit — confidence is high.
Why this matters
Certificate/key revocation checks exist specifically to prevent an application from trusting a host key that’s known to be compromised. A bypass in that mechanism weakens (without fully eliminating, given the stated high complexity) the guarantee that a JSch-based SSH client will correctly reject a revoked host key from known_hosts. Applications with a security posture that depends on host-key revocation enforcement — rather than treating known_hosts as an informal convenience — should prioritize the 2.28.6 upgrade even though this isn’t a low-complexity, easily automated exploit.
Frequently Asked Questions
What is CVE-2026-86231?
A high-complexity, low-severity (CVSS 3.7) improper certificate-revocation-check vulnerability in the mwiede/jsch Java SSH library, affecting versions through 2.28.5.
Which version fixes CVE-2026-86231? JSch 2.28.6 and later.
Is CVE-2026-86231 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog, and the project’s own record describes exploitation as difficult.
Data sourced from the mwiede/jsch project’s own GitHub repository, aggregated September 2026. See more vulnerability intelligence.