PT-2026-42707 · Go+1 · Golang.Org/X/Crypto+1

Published

2026-05-22

·

Updated

2026-05-22

·

CVE-2026-39828

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An issue exists where an SSH server authentication callback returning PartialSuccessError with non-nil Permissions caused those permissions to be silently discarded. This could lead to the removal of certificate restrictions, such as force-command, following the successful completion of a second factor authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-39828
GO-2026-5014

Affected Products

Golang.Org/X/Crypto
Golang.Org/X/Crypto/Ssh