CVE-2026-39835
Vulnerability Description
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh
Discussion (0)
Add Comment
No comments yet. Be the first!