Back to CVE List

CVE-2026-39835

Vulnerability Description

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
golang.org/x/crypto
Product
golang.org/x/crypto/ssh

External References

Discussion (0)

Add Comment

No comments yet. Be the first!