CVE-2026-39828
Vulnerability Description
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh
Discussion (0)
Add Comment
No comments yet. Be the first!