PT-2026-42716 · Go+1 · Golang.Org/X/Crypto+1

Published

2026-05-22

·

Updated

2026-05-22

·

CVE-2026-46595

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An authorization bypass exists in certain SSH server configurations. The issue occurs when a callback other than a public key is used, causing the source-address validation to be skipped.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-46595
GO-2026-5023

Affected Products

Golang.Org/X/Crypto
Golang.Org/X/Crypto/Ssh