PT-2026-42718 · Go+1 · Golang.Org/X/Crypto+1

Published

2026-05-22

·

Updated

2026-05-22

·

CVE-2026-46598

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description Certain crafted inputs allow the creation of an ed25519.PrivateKey by casting malformed wire bytes, which results in a panic when the key is used. A panic is an unexpected runtime error that causes a program to crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

CVE-2026-46598
GO-2026-5033

Affected Products

Golang.Org/X/Crypto
Golang.Org/X/Crypto/Ssh/Agent