CVE-2026-39832
Critical · CVSS 9.1golang.org/x/crypto/ssh/agent — Insecure Deserialization / Improper Privilege Management - SSH agent constraint extension stripping
- CVSS
- 9.1
- nvd
- EPSS
- 0.60%
- 46th pct
- KEV
- No
- Class
- oss containerizable
- CWE-502, CWE-281
Description
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
Search profile — drives PoC discovery
Symbols restrict-destination-v00@openssh.comNewKeyringconstraint extensionsAddedKeyconstraintExtensionserializeConstraintkeyringAddToAgentagent.KeyforwardKeyRemoteAgentdestConstraint
Keywords CVE-2026-39832GO-2026-5006golang crypto ssh agentrestrict-destination-v00@openssh.comNewKeyring constraintssh agent destination restriction bypassgolang x/crypto agent constraint extensionssh key forwarding unrestrictedgolang ssh agent serializationCWE-502 CWE-281 ssh agent
Versions: golang.org/x/crypto versions prior to the patch commit cl/778642 / issue #79435
Affected packages
| Go | golang.org/x/crypto | 0 → 0.52.0 |
References
- https://go.dev/cl/778640
- https://go.dev/cl/778641
- https://go.dev/issue/79435
- https://groups.google.com/g/golang-announce/c/a082jnz-LvI
- https://pkg.go.dev/vuln/GO-2026-5006
- https://access.redhat.com/errata/RHSA-2026:35833
- https://access.redhat.com/errata/RHSA-2026:36199
- https://access.redhat.com/errata/RHSA-2026:36319
- https://access.redhat.com/errata/RHSA-2026:36625
- https://access.redhat.com/errata/RHSA-2026:36648
- https://access.redhat.com/errata/RHSA-2026:36651
- https://access.redhat.com/errata/RHSA-2026:36796
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z