Back to search
CVE-2026-39835
Published: May 22, 2026
Modified: May 22, 2026
PUBLISHED
Description
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
| Vendor | Product | Versions |
|---|---|---|
golang.org/x/crypto | golang.org/x/crypto/ssh | affected 0 - < 0.52.0 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now