CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46595

Critical · CVSS 10.0

golang.org/x/crypto ssh — Authorization bypass / incorrect authentication check in SSH server callback handling (CWE-863, CWE-303)

CVSS
10.0
nvd
EPSS
0.50%
41th pct
KEV
No
Class
oss containerizable
CWE-863, CWE-303

Description

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

Search profile — drives PoC discovery

Symbols ServerConfigPublicKeyCallbackKeyboardInteractiveCallbackPasswordCallbackBannerCallbacksource-addressGSSAPIWithMICConfigallowedBySourceAddressauthenticatessh.ServerConnServerAuthCallback
Keywords CVE-2026-46595CVE-2024-45337golang x/crypto ssh authorization bypassssh server source-address validation bypassGO-2026-5023golang ssh callback authentication bypassPublicKeyCallback source address skipgolang ssh CWE-863golang ssh CWE-303RHSA-2026:23262
Versions: golang.org/x/crypto versions prior to the patch introduced in CL 781642 (post CVE-2024-45337 fix)

Affected packages

Go golang.org/x/crypto 0 → 0.52.0

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z