CVE Database
/

CVE-2025-58181

Back to search

CVE-2025-58181

Published: Nov 19, 2025

Modified: Nov 20, 2025

PUBLISHED

Description

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

VendorProductVersions

golang.org/x/crypto

golang.org/x/crypto/ssh

affected
0 - < 0.45.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now