CVE-2026-65058
Received Received - Intake

Confirmation-Binding Flaw in Trezor Safe Firmware

Vulnerability report for CVE-2026-65058, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker could present calldata to a victim then supply a different tail that changes the signed transaction. Fixed in 70c9b0c.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
trezor safe 70c9b0c

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-358 The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Trezor Safe 3, Safe 5, and Safe 7 firmware has a flaw where the device confirms only the initial part of calldata during Ethereum transaction signing. The signature, however, commits to the full calldata stream. An attacker could trick a victim into signing a transaction with one calldata chunk but later replace it with a different tail, altering the transaction details without detection.

Detection Guidance

This vulnerability is specific to Trezor Safe devices and involves firmware flaws in transaction signing. Detection requires checking the firmware version of Trezor Safe 3, Safe 5, or Safe 7 devices. Use the Trezor Suite or CLI tools to verify the firmware version. If the version is below the fixed commit 70c9b0c, the device is vulnerable.

Impact Analysis

If you use a vulnerable Trezor device for Ethereum transactions, an attacker could manipulate the signed transaction after you confirm it. This could lead to unauthorized transfers, contract interactions, or other unintended actions on your behalf, potentially resulting in financial loss or data exposure.

Compliance Impact

This vulnerability could undermine compliance with GDPR by enabling unauthorized data transactions or modifications. For HIPAA, it may risk integrity of health-related transactions. Organizations using vulnerable devices may face legal and regulatory penalties due to insufficient transaction integrity controls.

Mitigation Strategies

Update the firmware of all Trezor Safe 3, Safe 5, and Safe 7 devices to version 70c9b0c or later. Avoid using these devices for contract interactions until the update is applied. Review recent transaction confirmations for any unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65058. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart