Back to CVE List

CVE-2026-39828

Vulnerability Description

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh

External References

Discussion (0)

Add Comment

No comments yet. Be the first!