CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-39832

Critical · CVSS 9.1

golang.org/x/crypto/ssh/agent — Insecure Deserialization / Improper Privilege Management - SSH agent constraint extension stripping

CVSS
9.1
nvd
EPSS
0.60%
46th pct
KEV
No
Class
oss containerizable
CWE-502, CWE-281

Description

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

Search profile — drives PoC discovery

Symbols restrict-destination-v00@openssh.comNewKeyringconstraint extensionsAddedKeyconstraintExtensionserializeConstraintkeyringAddToAgentagent.KeyforwardKeyRemoteAgentdestConstraint
Keywords CVE-2026-39832GO-2026-5006golang crypto ssh agentrestrict-destination-v00@openssh.comNewKeyring constraintssh agent destination restriction bypassgolang x/crypto agent constraint extensionssh key forwarding unrestrictedgolang ssh agent serializationCWE-502 CWE-281 ssh agent
Versions: golang.org/x/crypto versions prior to the patch commit cl/778642 / issue #79435

Affected packages

Go golang.org/x/crypto 0 → 0.52.0

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z