Improper Signature Verification in Yubico YubiKey Products Affects Security
CVE-2025-29991
2.2LOW
What is CVE-2025-29991?
Yubico's YubiKey versions 5.4.1 to 5.7.3 prior to 5.7.4 exhibit a vulnerability in the implementation of the FIDO CTAP PIN/UV Auth Protocol Two. This flaw causes the device to use the signature length from the earlier CTAP PIN/UV Auth Protocol One, even when the more secure Protocol Two is intended to be active. As a result, the verification of signatures is incomplete, potentially allowing for unauthorized access or security breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
YubiKey 5.4.1 < 5.7.4
References
CVSS V3.1
Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
