golang.org/x/crypto/ssh vulnerability

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

Published 22 May 2026Updated 11 Sep 202659 sources
CVSS 5.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.