CVE-2026-39827
Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
22 mai 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
golang.org/x/crypto · golang.org/x/crypto/sshQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →