golang.org/x/crypto/ssh/agent
4 known vulnerabilities in golang.org/x/crypto/ssh/agent, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-46598 CVSS 5.3 medium For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.
- CVE-2026-39833 CVSS 9.1 critical The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key…
- CVE-2026-39832 CVSS 9.1 critical When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request…
- CVE-2025-47914 CVSS 5.3 medium SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the…