CVE-2026-46595
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
- Published May 22, 2026
- CVSS 10.0 critical
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
- Red Hat Cert Manager support for Red Hat OpenShift release
- Red Hat Cluster Observability Operator
- Red Hat Cryostat
- Red Hat DevWorkspace Operator
- Red Hat Logging Subsystem for Red Hat OpenShift
- Red Hat Multicluster Engine for Kubernetes
- Red Hat OpenShift API for Data Protection
- Red Hat RHEM
- golang.org/x/crypto/ssh