golang.org/x/crypto/ssh vulnerability

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

Published 22 May 2026Updated 11 Sep 202659 sources
CVSS 5.3

Source timeline

CVE record published by NVDView source ↗