7.5

CVE-2026-56855

Medienbericht

Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Golang ≫ Crypto SwPlatform go Version < 0.56.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.316
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://go.dev/cl/826524
Patch
https://go.dev/issue/81317
Vendor Advisory
Issue Tracking
https://groups.google.com/g/golang-announce/c/1y3fb2np35U
Vendor Advisory
Mailing List
https://pkg.go.dev/vuln/GO-2026-6355
Vendor Advisory