CVE-2026-46595
Critical · CVSS 10.0golang.org/x/crypto ssh — Authorization bypass / incorrect authentication check in SSH server callback handling (CWE-863, CWE-303)
- CVSS
- 10.0
- nvd
- EPSS
- 0.50%
- 41th pct
- KEV
- No
- Class
- oss containerizable
- CWE-863, CWE-303
Description
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
Search profile — drives PoC discovery
Symbols ServerConfigPublicKeyCallbackKeyboardInteractiveCallbackPasswordCallbackBannerCallbacksource-addressGSSAPIWithMICConfigallowedBySourceAddressauthenticatessh.ServerConnServerAuthCallback
Keywords CVE-2026-46595CVE-2024-45337golang x/crypto ssh authorization bypassssh server source-address validation bypassGO-2026-5023golang ssh callback authentication bypassPublicKeyCallback source address skipgolang ssh CWE-863golang ssh CWE-303RHSA-2026:23262
Versions: golang.org/x/crypto versions prior to the patch introduced in CL 781642 (post CVE-2024-45337 fix)
Affected packages
| Go | golang.org/x/crypto | 0 → 0.52.0 |
References
- https://go.dev/cl/781642
- https://go.dev/issue/79570
- https://groups.google.com/g/golang-announce/c/a082jnz-LvI
- https://pkg.go.dev/vuln/GO-2026-5023
- https://access.redhat.com/errata/RHSA-2026:23262
- https://access.redhat.com/errata/RHSA-2026:23264
- https://access.redhat.com/errata/RHSA-2026:26546
- https://access.redhat.com/errata/RHSA-2026:26547
- https://access.redhat.com/errata/RHSA-2026:30650
- https://access.redhat.com/errata/RHSA-2026:30651
- https://access.redhat.com/errata/RHSA-2026:33524
- https://access.redhat.com/errata/RHSA-2026:33531
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z