CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
- Published May 22, 2026
- CVSS 5.3 medium
- 0.7% chance of exploitation in the next 30 days (EPSS)
- A fix is available