Golang.Org X Crypto Golang.Org X Crypto Ssh vulnerabilities
3 known vulnerabilities affecting golang.org/x_crypto_golang.org_x_crypto_ssh.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-58181MEDIUMCVSS 5.3fixed in 0.45.02025-11-19
CVE-2025-58181 [MEDIUM] CWE-770 CVE-2025-58181: SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specifie
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
cvelistv5nvd
CVE-2025-22869HIGHCVSS 7.5fixed in 0.35.02025-02-26
CVE-2025-22869 [HIGH] CWE-770 CVE-2025-22869: SSH servers which implement file transfer protocols are vulnerable to a denial of service attack fro
SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.
cvelistv5nvd
CVE-2024-45337CRITICALCVSS 9.1fixed in 0.31.02024-12-12
CVE-2024-45337 [CRITICAL] CVE-2024-45337: Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConf
Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH prot
cvelistv5nvd