MEDIUM5.3
GHSA-j5w8-q4qc-rx2x
golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption
Quick fix
GHSA-j5w8-q4qc-rx2x — golang.org/x/crypto: upgrade to the fixed version with the command below.
go get golang.org/x/crypto@v0.45.0Details
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
Are you affected?
Enter the version of the package you're using.