CRITICAL10.0
GHSA-x527-x647-q7gg
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
Quick fix
GHSA-x527-x647-q7gg — golang.org/x/crypto: upgrade to the fixed version with the command below.
go get golang.org/x/crypto@v0.52.0Details
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-46595[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337[ADVISORY]
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json[WEB]
- https://pkg.go.dev/vuln/GO-2026-5023[WEB]
- https://groups.google.com/g/golang-announce/c/a082jnz-LvI[WEB]
- https://go.dev/issue/79570[WEB]
- https://go.dev/cl/781642[WEB]
- https://cs.opensource.google/go/x/crypto[PACKAGE]
- https://bugzilla.redhat.com/show_bug.cgi?id=2480689[WEB]
- https://access.redhat.com/security/cve/CVE-2026-46595[WEB]
- https://access.redhat.com/errata/RHSA-2026:41036[WEB]
- https://access.redhat.com/errata/RHSA-2026:41019[WEB]
- https://access.redhat.com/errata/RHSA-2026:40945[WEB]
- https://access.redhat.com/errata/RHSA-2026:40118[WEB]
- https://access.redhat.com/errata/RHSA-2026:37387[WEB]
- https://access.redhat.com/errata/RHSA-2026:37275[WEB]
- https://access.redhat.com/errata/RHSA-2026:36820[WEB]
- https://access.redhat.com/errata/RHSA-2026:36808[WEB]
- https://access.redhat.com/errata/RHSA-2026:36797[WEB]
- https://access.redhat.com/errata/RHSA-2026:36796[WEB]
- https://access.redhat.com/errata/RHSA-2026:36651[WEB]
- https://access.redhat.com/errata/RHSA-2026:36648[WEB]
- https://access.redhat.com/errata/RHSA-2026:36207[WEB]
- https://access.redhat.com/errata/RHSA-2026:33531[WEB]
- https://access.redhat.com/errata/RHSA-2026:33524[WEB]
- https://access.redhat.com/errata/RHSA-2026:30651[WEB]
- https://access.redhat.com/errata/RHSA-2026:30650[WEB]
- https://access.redhat.com/errata/RHSA-2026:26547[WEB]
- https://access.redhat.com/errata/RHSA-2026:26546[WEB]
- https://access.redhat.com/errata/RHSA-2026:23264[WEB]
- https://access.redhat.com/errata/RHSA-2026:23262[WEB]