golang.org/x/crypto/ssh vulnerability

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.

Published 22 May 2026Updated 11 Sep 202656 sources
CVSS 6.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.