CVE-2026-46597
published 2026-05-22CVE-2026-46597: An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.47%
39.8th percentile
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Affected
184 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-rhel8-operator | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-rhel8_1782891812 | — | — |
| advanced-cluster-security | rhacs-scanner-slim-rhel8_1782891812 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel8_1783357116 | — | — |
| assisted | agent-preinstall-image-builder-rhel9 | — | — |
| buildah_project | buildah | — | — |
| cert-manager | jetstack-cert-manager-acmesolver-rhel9 | — | — |
| cert-manager | jetstack-cert-manager-rhel9 | — | — |
| compliance | openshift-security-profiles-operator-bundle | — | — |
| compliance | openshift-security-profiles-rhel8-operator | — | — |
| confidential-containers | trustee | — | — |
| container-native-virtualization | virt-api-rhel9 | — | — |
| container-native-virtualization | virt-artifacts-server-rhel9 | — | — |
| container-native-virtualization | virt-controller-rhel9 | — | — |
| container-native-virtualization | virt-exportproxy-rhel9 | — | — |
| container-native-virtualization | virt-exportserver-rhel9 | — | — |
| container-native-virtualization | virt-handler-rhel9 | — | — |
| container-native-virtualization | virt-launcher-rhel9 | — | — |
| container-native-virtualization | virt-operator-rhel9 | — | — |
| container-tools_rhel8 | buildah | — | — |
| container-tools_rhel8 | podman | — | — |
| cryostat | cryostat-storage-rhel9 | — | — |
| devspaces | traefik-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
vendor_redhat·2026-05-22·CVSS 7.5
CVE-2026-46597 [HIGH] CWE-681 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
A flaw was found in golang.org/x/crypto/ssh. A remote attacker could send specially crafted inputs to the AES-GCM packet decoder. This could lead to an incorrectly placed cast from bytes to an integer, causing a server-side panic and resulting in a Denial of Service (DoS) for the affected system.
Statement: This Important denial of service flaw in `golang.org/x/crypto/ssh` allows a remote attacker to trigger a server-side panic by sending specially crafted inputs to the AES-GCM packet decoder. This vulnerability could lead to service unavailability in
GHSA
golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic
ghsa·2026-06-25
CVE-2026-46597 [HIGH] CWE-704 golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic
golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-46597 rootlesskit: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 rootlesskit: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 rootlesskit: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 nng: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 nng: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 nng: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 hcloud: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 hcloud: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 hcloud: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 cri-o: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 cri-o: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 cri-o: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 kubernetes1.33: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 kubernetes1.33: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 kubernetes1.33: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 restic: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 restic: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 restic: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 kubernetes1.34: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 kubernetes1.34: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 kubernetes1.34: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 restic: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 restic: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 restic: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 podman: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 podman: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 podman: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 opentofu: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 opentofu: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 opentofu: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 tailscale: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 tailscale: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 tailscale: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang-github-git-5: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang-github-git-5: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 golang-github-git-5: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 headscale: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 headscale: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 headscale: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 gvisor-tap-vsock: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 gvisor-tap-vsock: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 gvisor-tap-vsock: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 containers-common: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 containers-common: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 containers-common: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 kubernetes1.30: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 kubernetes1.30: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 kubernetes1.30: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 cri-o1.30: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 cri-o1.30: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 cri-o1.30: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 pack: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 pack: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 pack: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 pack: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 pack: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 pack: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 gopass-hibp: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 gopass-hibp: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 gopass-hibp: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 vhs: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 vhs: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 vhs: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 inspektor-gadget: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 inspektor-gadget: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 inspektor-gadget: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 docker-buildx: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 docker-buildx: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 docker-buildx: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 google-guest-agent: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 google-guest-agent: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 google-guest-agent: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 transifex-client: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 transifex-client: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 transifex-client: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 docker-compose: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 docker-compose: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 docker-compose: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 gh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 gh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 gh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 cri-o1.31: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 cri-o1.31: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 cri-o1.31: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 buildah: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 buildah: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 buildah: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 kubernetes1.32: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 kubernetes1.32: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 kubernetes1.32: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang-github-acme-lego: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang-github-acme-lego: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 golang-github-acme-lego: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 clash-meta: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 clash-meta: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 clash-meta: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 kubernetes1.31: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 kubernetes1.31: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 kubernetes1.31: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 gopass-jsonapi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 gopass-jsonapi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 gopass-jsonapi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 moby-engine: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 moby-engine: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 moby-engine: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Discussion:
cli [ 29.x] Elapsed: 2s
❯ go mod why -m golang.org/x/crypto/ssh
# golang.org/x/crypto/ssh
(main module does not need module golang.org/x/crypto/ssh)
cli [ 29.x]
❯ cd ../moby/
moby [ docker-29.x][?]
❯ go mod why -m golang.org/x/crypto/ssh
# golang.org/x/crypto/ssh
(main module does not need module g
Bugzilla
CVE-2026-46597 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 gh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 gh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 gh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 cri-o1.34: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 cri-o1.34: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 cri-o1.34: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 vagrant: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 vagrant: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 vagrant: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 kubernetes1.36: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 kubernetes1.36: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 kubernetes1.36: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 clash-meta: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 clash-meta: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 clash-meta: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 cri-o1.33: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 cri-o1.33: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 cri-o1.33: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 DankMaterialShell: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 DankMaterialShell: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 DankMaterialShell: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 age: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 age: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 age: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 cri-o1.32: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 cri-o1.32: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 cri-o1.32: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 k9s: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 k9s: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 k9s: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 ollama: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 ollama: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 ollama: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 cri-o1.35: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 cri-o1.35: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 cri-o1.35: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 trayscale: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 trayscale: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 trayscale: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 cheat: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 cheat: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 cheat: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 gopass: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 gopass: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 gopass: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 docker-buildkit: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 docker-buildkit: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 docker-buildkit: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 kubernetes1.35: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 kubernetes1.35: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 kubernetes1.35: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 nebula: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 nebula: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 nebula: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 incus: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 incus: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 incus: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
CVE-2026-46597 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 age: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
bugzilla·2026-07-30·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 age: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
CVE-2026-46597 age: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Bugzilla
CVE-2026-46597 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
bugzilla·2026-05-22·CVSS 7.5
CVE-2026-46597 [HIGH] CVE-2026-46597 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
CVE-2026-46597 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
2026-05-22
Published