{"id":"CVE-2026-39827","aliases":["GO-2026-5016","GHSA-qpw4-5x99-6vjp"],"title":"Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh","summary":"Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","vendor":"x","product":"golang.org/x/crypto","ecosystem":"go","affected":["golang.org/x/crypto < 0.52.0"],"patched":["golang.org/x/crypto 0.52.0"],"published":"2026-05-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T10:41:47.670428128Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GO-2026-5016","references":[{"url":"https://go.dev/issue/35127"},{"url":"https://go.dev/cl/781320"},{"url":"https://groups.google.com/g/golang-announce/c/a082jnz-LvI"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39827.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-39827"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480682"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-39827"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39827"},{"url":"https://pkg.go.dev/vuln/GO-2026-5016"},{"url":"https://access.redhat.com/errata/RHSA-2026:43692"},{"url":"https://access.redhat.com/errata/RHSA-2026:62391"},{"url":"https://access.redhat.com/errata/RHSA-2026:66561"},{"url":"https://access.redhat.com/errata/RHSA-2026:37387"},{"url":"https://access.redhat.com/errata/RHSA-2026:57194"},{"url":"https://github.com/advisories/GHSA-qpw4-5x99-6vjp"}],"tags":["osv","go","csaf","vex","red-hat","ghsa"],"epss":0.00279,"epssPercentile":0.20687,"cvssSource":"vendor","cwe":["CWE-772","CWE-924"],"ingestedAt":"2026-06-26T16:43:14.196Z","slug":"CVE-2026-39827","body":"## Overview\n\nAn authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.\n\n## Affected packages\n\n- `golang.org/x/crypto < 0.52.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `golang.org/x/crypto 0.52.0`\n\n## Vendor advisories\n\n- **RHSA-2026:43692** · Red Hat · fixed in: OpenShift API for Data Protection 1.6 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43692)\n- **RHSA-2026:62391** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62391)\n- **RHSA-2026:66561** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66561)\n- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)\n- **RHSA-2026:57194** · Red Hat · fixed in: multicluster engine for Kubernetes 2.11 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:57194)\n- **Red Hat VEX** · Moderate · affected: Cryostat 4, Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, … · no fix planned: Red Hat Hardened Images, Cryostat 4, Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39827.json)","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}