golang.org/x/crypto/ssh

15 known vulnerabilities in golang.org/x/crypto/ssh, 5 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-78662 CVSS 7.5 high Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the…
  • CVE-2026-56855 CVSS 7.5 high Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection…
  • CVE-2026-56854 CVSS 7.5 high The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback…
  • CVE-2026-46597 CVSS 7.5 high An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
  • CVE-2026-46595 CVSS 10.0 critical Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed…
  • CVE-2026-39835 CVSS 5.3 medium SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by…
  • CVE-2026-39834 CVSS 9.1 critical When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation…
  • CVE-2026-39831 CVSS 9.1 critical The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the…
  • CVE-2026-39830 CVSS 9.1 critical A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The…
  • CVE-2026-39829 CVSS 7.5 high The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus…
  • CVE-2026-39828 CVSS 6.3 medium When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently…
  • CVE-2026-39827 CVSS 6.5 medium An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually…
  • CVE-2025-58181 CVSS 5.3 medium SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker…
  • CVE-2025-22869 CVSS 7.5 high SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key…
  • CVE-2024-45337 CVSS 9.1 critical Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be…