{"id":"CVE-2026-46598","title":"golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input (CVE-2026-46598)","summary":"A flaw was found in golang.org/x/crypto/ssh/agent. An attacker could provide specially crafted inputs that, when processed, lead to the creation of an ed25519.PrivateKey by casting malformed wire bytes. This improper input handling can cau…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cvssSource":"vendor","cwe":["CWE-1287","CWE-129"],"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4.22","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","builds_for_red_hat_openshift","external_secrets_operator_for_red_hat_openshift","multicluster_engine_for_kubernetes","openshift_pipelines","openshift_serverless","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 4","ai_inference_server","ceph_storage 9","edge_manager 1","enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","hardened_images","openshift_ai_rhoai","openshift_container_platform 4","openshift_dev_workspaces_operator","openshift_gitops","openshift_virtualization 4","openstack_platform 16.2","openstack_platform 17.1","openstack_platform 18.0","quay 3","trusted_artifact_signer","openshift_api_for_data_protection 1.6","openshift_data_foundation 4.22","multicluster_engine_for_kubernetes 2.11"],"patched":["openshift_api_for_data_protection 1.6","hardened_images","openshift_data_foundation 4.22","multicluster_engine_for_kubernetes 2.11"],"published":"2026-05-22","updated":"2026-09-21","sourceUpdated":"2026-09-21T11:38:20+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46598.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46598.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-46598"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2480679"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-46598"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46598"},{"url":"https://go.dev/cl/781360"},{"url":"https://go.dev/issue/79596"},{"url":"https://groups.google.com/g/golang-announce/c/a082jnz-LvI"},{"url":"https://pkg.go.dev/vuln/GO-2026-5033"},{"url":"https://access.redhat.com/errata/RHSA-2026:43692"},{"url":"https://access.redhat.com/errata/RHSA-2026:62391"},{"url":"https://access.redhat.com/errata/RHSA-2026:66561"},{"url":"https://access.redhat.com/errata/RHSA-2026:37387"},{"url":"https://access.redhat.com/errata/RHSA-2026:57194"},{"url":"https://github.com/advisories/GHSA-9m57-25v3-79x9"}],"tags":["csaf","vex","red-hat","ghsa","go"],"epss":0.00412,"epssPercentile":0.35112,"ecosystem":"go","ingestedAt":"2026-06-26T16:43:14.202Z","slug":"CVE-2026-46598","body":"## Overview\n\nA flaw was found in golang.org/x/crypto/ssh/agent. An attacker could provide specially crafted inputs that, when processed, lead to the creation of an ed25519.PrivateKey by casting malformed wire bytes. This improper input handling can cause the program to panic and crash, resulting in a Denial of Service (DoS) for the affected component.\n\n## Vendor advisories\n\n- **RHSA-2026:43692** · Red Hat · fixed in: OpenShift API for Data Protection 1.6 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43692)\n- **RHSA-2026:62391** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62391)\n- **RHSA-2026:66561** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66561)\n- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)\n- **RHSA-2026:57194** · Red Hat · fixed in: multicluster engine for Kubernetes 2.11 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:57194)\n- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, External Secrets Operator for Red Hat OpenShift, Multicluster Engine for Kubernetes, OpenShift Pipelines, OpenShift Serverless, … · no fix planned: Red Hat Hardened Images, Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, External Secrets Operator for Red Hat OpenShift, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46598.json)\n\n**golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input** — rated Moderate by Red Hat. Released 2026-05-22, updated 2026-09-21.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- External Secrets Operator for Red Hat OpenShift\n- Multicluster Engine for Kubernetes\n- OpenShift Pipelines\n- OpenShift Serverless\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat AI Inference Server\n- Red Hat Ceph Storage 9\n- Red Hat Edge Manager 1\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Hardened Images\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Dev Workspaces Operator\n- Red Hat OpenShift GitOps\n- Red Hat OpenShift Virtualization 4\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat OpenStack Platform 18.0\n- Red Hat Quay 3\n- Red Hat Trusted Artifact Signer\n\nFixed:\n\n- OpenShift API for Data Protection 1.6\n- Red Hat Hardened Images\n- Red Hat Openshift Data Foundation 4.22\n- multicluster engine for Kubernetes 2.11\n\nNo fix planned:\n\n- Red Hat Hardened Images\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- External Secrets Operator for Red Hat OpenShift\n- Multicluster Engine for Kubernetes\n- OpenShift Pipelines\n- OpenShift Serverless\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat AI Inference Server\n- Red Hat Ceph Storage 9\n- Red Hat Edge Manager 1\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Dev Workspaces Operator\n- Red Hat OpenShift GitOps\n- Red Hat OpenShift Virtualization 4\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat OpenStack Platform 18.0\n- Red Hat Quay 3\n- Red Hat Trusted Artifact Signer\n\nNot affected:\n\n- OpenShift API for Data Protection 1.6\n- Red Hat Openshift Data Foundation 4.22\n- multicluster engine for Kubernetes 2.11\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied. https://access.redhat.com/errata/RHSA-2026:43692\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:62391\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:66561\n\nWorkarounds / mitigations:\n\n- To mitigate this issue, restrict the exposure of the SSH agent to untrusted sources. Avoid enabling SSH agent forwarding when connecting to untrusted hosts or environments. Ensure that applications interacting with `golang.org/x/crypto/ssh/agent` validate all inputs to prevent malformed data from being processed. Reloading or restarting SSH services may be required for changes to take effect.\n\n## Package advisory (CVE-2026-46598)\n\nAffected packages:\n\n- `golang.org/x/crypto/ssh/agent < 0.52.0`\n\nPatched in:\n\n- `golang.org/x/crypto/ssh/agent 0.52.0`\n\nSource: https://github.com/advisories/GHSA-9m57-25v3-79x9","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}