Back to overview

CVE-2026-46595

CRITICAL
10.0
CVSS 3.1
Description
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

Metadata

CVE ID
CVE-2026-46595
State
PUBLISHED
Assigner
Go
Reserved
2026-05-15 17:35 UTC
Published
2026-05-22 02:31 UTC
Last updated
2026-07-27 12:05 UTC
Primary CWE
CWE-863
CWE-863 Incorrect Authorization
Vendor / Product
golang.org/x/crypto / golang.org/x/crypto/ssh
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
golang.org/x/crypto golang.org/x/crypto/ssh 0 < 0.52.0
Weakness (CWE)
CWESourceDescription
cna CWE-863: Incorrect Authorization
CWE-303 adp Incorrect Implementation of Authentication Algorithm
CWE-863 adp CWE-863 Incorrect Authorization
CVSS scores (2)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
7.1 HIGH 3.1 adp CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Back to overview