golang.org/x/crypto/ssh vulnerability

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.

Published 22 May 2026Updated 11 Sep 202656 sources
CVSS 6.3

Source timeline

CVE record published by NVDView source ↗