golang / crypto
15 known vulnerabilities in golang crypto.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-42508 | Medium | 7.3% | 9.1 | Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked… | |
| CVE-2026-39830 | Medium | 0.6% | 9.1 | A malicious SSH peer could send unsolicited global request responses to fill an … | |
| CVE-2026-39832 | Medium | 0.6% | 9.1 | When adding a key to a remote agent constraint extensions such as restrict-desti… | |
| CVE-2026-39834 | Medium | 0.5% | 9.1 | When writing data larger than 4GB in a single Write call on an SSH channel, an i… | |
| CVE-2026-46595 | Medium | 0.5% | 10.0 | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server … | |
| CVE-2026-46597 | Medium | 0.5% | 7.5 | An incorrectly placed cast from bytes to int allowed for server-side panic in th… | |
| CVE-2026-39829 | Medium | 0.5% | 7.5 | The RSA and DSA public key parsers did not enforce size limits on key parameters… | |
| CVE-2026-39831 | Medium | 0.4% | 9.1 | The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@open… | |
| CVE-2026-39833 | Medium | 0.4% | 9.1 | The in-memory keyring returned by NewKeyring() silently accepted keys with the C… | |
| CVE-2026-56855 | Medium | 0.4% | 7.5 | Previously, after a channel has been established, a malicious peer could send cr… | |
| CVE-2026-78662 | Medium | 0.3% | 7.5 | Previously, a channel registered in the mux's chanList is not usable until it is… | |
| CVE-2026-39835 | Low | 0.5% | 5.3 | SSH servers which use CertChecker as a public key callback without setting IsUse… | |
| CVE-2026-46598 | Low | 0.4% | 5.3 | For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malfor… | |
| CVE-2026-39828 | Low | 0.4% | 6.3 | When an SSH server authentication callback returned PartialSuccessError with non… | |
| CVE-2026-39827 | Low | 0.3% | 6.5 | An authenticated SSH client that repeatedly opened channels which were rejected … |