---
id: CVE-2026-46598
aliases:
  - GO-2026-5033
  - GHSA-9m57-25v3-79x9
title: >-
  Invoking pathological inputs can lead to client panic in
  golang.org/x/crypto/ssh/agent
summary: >-
  Invoking pathological inputs can lead to client panic in
  golang.org/x/crypto/ssh/agent
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
vendor: x
product: golang.org/x/crypto
ecosystem: go
affected:
  - golang.org/x/crypto < 0.52.0
patched:
  - golang.org/x/crypto 0.52.0
published: '2026-05-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T10:41:48.813027241Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-5033'
references:
  - url: 'https://go.dev/issue/79596'
  - url: 'https://go.dev/cl/781360'
  - url: 'https://groups.google.com/g/golang-announce/c/a082jnz-LvI'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46598.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-46598'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2480679'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-46598'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46598'
  - url: 'https://pkg.go.dev/vuln/GO-2026-5033'
  - url: 'https://access.redhat.com/errata/RHSA-2026:43692'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62391'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66561'
  - url: 'https://access.redhat.com/errata/RHSA-2026:37387'
  - url: 'https://access.redhat.com/errata/RHSA-2026:57194'
  - url: 'https://github.com/advisories/GHSA-9m57-25v3-79x9'
tags:
  - osv
  - go
  - csaf
  - vex
  - red-hat
  - ghsa
epss: 0.00515
epssPercentile: 0.41423
cvssSource: vendor
cwe:
  - CWE-1287
  - CWE-129
ingestedAt: '2026-06-26T16:43:14.202Z'
---

## Overview

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.

## Affected packages

- `golang.org/x/crypto < 0.52.0`

## Remediation

Upgrade to a patched release:

- `golang.org/x/crypto 0.52.0`

## Vendor advisories

- **RHSA-2026:43692** · Red Hat · fixed in: OpenShift API for Data Protection 1.6 · released 2026-07-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:43692)
- **RHSA-2026:62391** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62391)
- **RHSA-2026:66561** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:66561)
- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)
- **RHSA-2026:57194** · Red Hat · fixed in: multicluster engine for Kubernetes 2.11 · released 2026-08-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:57194)
- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, External Secrets Operator for Red Hat OpenShift, Multicluster Engine for Kubernetes, OpenShift Pipelines, OpenShift Serverless, … · no fix planned: Red Hat Hardened Images, Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, External Secrets Operator for Red Hat OpenShift, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46598.json)
