Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:golang/golang.org/x/crypto/ssh

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

This security advisory addresses multiple vulnerabilities in the embedded golang.org/x/crypto/ssh package used by Red Hat OpenShift Builds. The update to version v0.56.0 fixes an authentication bypass (CVE-2026-56854) and two deadlock vulnerabilities (CVE-2026-56855 and CVE-2026-78662). The affected versions include 0.15.6-bp160.2.1.aarch64 and 0.15.6-bp160.2.1.ppc64le. Users of Red Hat OpenShift Builds 1.9.0 are recommended to upgrade to 1.9.1 to address these issues.

Join the discussion

CVE-2026-56855 is a high-severity vulnerability in the golang.org/x/crypto/ssh package where a malicious peer can send crafted messages after a channel is established that cause the entire connection to deadlock. The issue arises from allocation of resources without limits or throttling, leading to blocking behavior. The fix involves handling all RFC 4254 channel messages explicitly and treating unexpected messages as protocol errors that cause connection teardown instead of buffering and blocking.

Join the discussion

CVE-2026-56854 is a high-severity authorization vulnerability in the golang.org/x/crypto/ssh package. The flaw involves incorrect enforcement of the source-address restriction in authentication callbacks, where this restriction was only applied to some authentication paths but ignored in others. This inconsistency could allow unauthorized access if source-address restrictions are used as a security control.

Join the discussion

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

Join the discussion

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

Join the discussion

CVE-2026-39834 is a critical integer overflow vulnerability in the golang.org/x/crypto/ssh package. It occurs when writing data larger than 4GB in a single Write call on an SSH channel, causing an integer overflow in the internal payload size calculation. This overflow results in an infinite loop that sends empty packets without progress, leading to a denial of service condition. The issue stems from using a truncated integer type for size comparison, which has been addressed by switching to int64 to prevent overflow.

Join the discussion

A critical authentication bypass vulnerability (CVE-2026-39831) exists in golang.org/x/crypto/ssh affecting FIDO/U2F security key types. The Verify() method fails to check the User Presence flag, allowing signatures generated without physical user interaction to be accepted. This flaw enables unauthorized use of hardware security keys without user touch unless mitigated by a specific extension in Permissions.Extensions. The vulnerability has a high CVSS score of 9.1 and impacts authentication security.

Join the discussion

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

Join the discussion

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

Join the discussion

CVE-2026-39827 is a medium severity vulnerability in the golang.org/x/crypto/ssh package that causes a memory leak. When an authenticated SSH client repeatedly opens channels that the server rejects, the rejected channels are not properly removed from the server's internal state. This leads to unbounded memory growth, which can crash the server process and disrupt all connected users.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Package: pkg:golang/golang.org/x/crypto/ssh
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses