---
id: CVE-2025-47913
title: >-
  golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic
  due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)
summary: >-
  A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic
  when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to
  requests expecting typed replies (e.g., List, Sign). The unmarshal layer
  produces an une…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-241
vendor: Red Hat
product: Red Hat Enterprise Linux AppStream E4S (v.8.6)
affected:
  - multicluster_engine_for_kubernetes
  - openshift_developer_tools_and_services
  - openshift_serverless
  - advanced_cluster_management_for_kubernetes 2
  - ansible_automation_platform 2
  - ceph_storage 6
  - edge_manager_preview
  - enterprise_linux 8
  - enterprise_linux_ai_rhel_ai
  - openshift_container_platform 4
  - openshift_gitops
  - openshift_virtualization 4
  - openstack_platform 16.2
  - ceph_storage_7_1_tools
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_6
  - enterprise_linux_appstream_tus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_0
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_eus_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - builds_for_red_hat_openshift 1.6.0
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_v_10
  - devworkspace_operator 0.39
  - openshift_api_for_data_protection 1.6
  - advanced_cluster_management_for_kubernetes 2.15
  - ceph_storage 7.1
  - ceph_storage 8
  - ceph_storage 9.0
  - container_native_virtualization 4.14
  - container_native_virtualization 4.16
  - container_native_virtualization 4.19
  - container_native_virtualization 4.20
patched:
  - ceph_storage_7_1_tools
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_aus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_6
  - enterprise_linux_appstream_tus_v_8_6
  - enterprise_linux_appstream_e4s_v_8_8
  - enterprise_linux_appstream_tus_v_8_8
  - enterprise_linux_appstream_e4s_v_9_0
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_eus_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - builds_for_red_hat_openshift 1.6.0
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_v_10
  - devworkspace_operator 0.39
  - openshift_api_for_data_protection 1.6
  - advanced_cluster_management_for_kubernetes 2.15
  - ceph_storage 7.1
  - ceph_storage 8
  - ceph_storage 9.0
  - container_native_virtualization 4.14
  - container_native_virtualization 4.16
  - container_native_virtualization 4.19
  - container_native_virtualization 4.20
  - openshift_ai 2.25
  - openshift_gitops 1.17
  - openshift_gitops 1.18
  - openshift_pipelines 1.2
  - openstack_platform 16.2
  - openstack_platform 17.1
  - openshift_data_foundation 4.20
  - quay 3.10
  - quay 3.12
  - quay 3.13
  - quay 3.14
  - quay 3.15
  - quay 3.16
published: '2025-11-13'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T16:30:06+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-47913.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-47913.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-47913'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2414943'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-47913'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-47913'
  - url: 'https://github.com/advisories/GHSA-hcg3-q754-cr77'
  - url: 'https://go.dev/cl/700295'
  - url: 'https://go.dev/issue/75178'
  - url: 'https://pkg.go.dev/vuln/GO-2025-4116'
  - url: 'https://access.redhat.com/errata/RHSA-2026:2769'
  - url: 'https://access.redhat.com/errata/RHSA-2026:14868'
  - url: 'https://access.redhat.com/errata/RHSA-2026:5167'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0436'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0545'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0753'
  - url: 'https://access.redhat.com/errata/RHSA-2026:10703'
  - url: 'https://access.redhat.com/errata/RHSA-2026:19634'
  - url: 'https://access.redhat.com/errata/RHSA-2026:4693'
  - url: 'https://access.redhat.com/errata/RHSA-2026:16701'
  - url: 'https://access.redhat.com/errata/RHSA-2026:16102'
  - url: 'https://access.redhat.com/errata/RHSA-2026:8325'
  - url: 'https://access.redhat.com/errata/RHSA-2026:4532'
  - url: 'https://access.redhat.com/errata/RHSA-2026:16702'
  - url: 'https://access.redhat.com/errata/RHSA-2026:12030'
  - url: 'https://access.redhat.com/errata/RHSA-2026:5222'
  - url: 'https://access.redhat.com/errata/RHSA-2026:11749'
  - url: 'https://access.redhat.com/errata/RHSA-2026:1084'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0437'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0470'
  - url: 'https://access.redhat.com/errata/RHSA-2025:22743'
  - url: 'https://github.com/golang/crypto'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00623
epssPercentile: 0.4765
aliases:
  - GHSA-56w8-48fp-6mgv
  - GO-2025-4116
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.755Z'
---

## Overview

A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an unexpected message type, which the client code does not handle, leading to panic("unreachable") or a nil-pointer dereference. A malicious agent or forwarded connection can exploit this to terminate the client process.

## Vendor advisories

- **RHSA-2026:2769** · Red Hat · fixed in: Red Hat Ceph Storage 7.1 Tools · released 2026-02-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:2769)
- **RHSA-2026:14868** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:14868)
- **RHSA-2026:5167** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-03-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:5167)
- **RHSA-2026:0436** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-01-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:0436)
- **RHSA-2026:0545** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-01-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:0545)
- **RHSA-2026:0753** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-01-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:0753)
- **RHSA-2026:10703** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream E4S (v.8.6), Red Hat Enterprise Linux AppStream TUS (v.8.6) · released 2026-04-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:10703)
- **RHSA-2026:19634** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream E4S (v.8.6), Red Hat Enterprise Linux AppStream TUS (v.8.6) · released 2026-05-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:19634)
- **RHSA-2026:4693** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-03-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:4693)
- **RHSA-2026:16701** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-05-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:16701)
- **RHSA-2026:16102** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.0) · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16102)
- **Red Hat VEX** · Important · affected: Multicluster Engine for Kubernetes, OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ansible Automation Platform 2, Red Hat Ceph Storage 6, … · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Edge Manager preview, Red Hat Enterprise Linux AI (RHEL AI), Red Hat OpenShift Container Platform 4, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-47913.json)

**golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS** — rated Important by Red Hat. Released 2025-11-13, updated 2026-09-25.

Affected:

- Multicluster Engine for Kubernetes
- OpenShift Developer Tools and Services
- OpenShift Serverless
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 6
- Red Hat Edge Manager preview
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2

Fixed:

- Red Hat Ceph Storage 7.1 Tools
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream AUS (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.6)
- Red Hat Enterprise Linux AppStream TUS (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.8)
- Red Hat Enterprise Linux AppStream TUS (v.8.8)
- Red Hat Enterprise Linux AppStream E4S (v.9.0)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream EUS (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Builds for Red Hat OpenShift 1.6.0
- Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- DevWorkspace Operator 0.39
- OpenShift API for Data Protection 1.6
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Ceph Storage 7.1
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9.0
- Red Hat Container Native Virtualization 4.14
- Red Hat Container Native Virtualization 4.16
- Red Hat Container Native Virtualization 4.19
- Red Hat Container Native Virtualization 4.20
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift GitOps 1.17
- Red Hat OpenShift GitOps 1.18
- Red Hat OpenShift Pipelines 1.2
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat Openshift Data Foundation 4.20
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.13
- Red Hat Quay 3.14
- Red Hat Quay 3.15
- Red Hat Quay 3.16

No fix planned:

- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Edge Manager preview
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2
- Multicluster Engine for Kubernetes
- OpenShift Developer Tools and Services
- OpenShift Serverless
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 6
- Red Hat Enterprise Linux 8

Not affected:

- Red Hat Enterprise Linux AppStream E4S (v.9.0)
- Builds for Red Hat OpenShift 1.6.0
- DevWorkspace Operator 0.39
- OpenShift API for Data Protection 1.6
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Ceph Storage 7.1
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9.0
- Red Hat Container Native Virtualization 4.14
- Red Hat Container Native Virtualization 4.16

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

For supported configurations, refer to:

https://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2026:2769
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:14868
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:5167

Workarounds / mitigations:

- No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

## Package advisory (CVE-2025-47913)

Affected packages:

- `golang.org/x/crypto/ssh/agent < 0.43.0`

Patched in:

- `golang.org/x/crypto/ssh/agent 0.43.0`

Source: https://osv.dev/vulnerability/GHSA-56w8-48fp-6mgv
