CVE-2026-56854Medium· 6.8▾ SunlitA flaw was found in golang.org/x/crypto/ssh. The component failed to properly enforce source-address restrictions for several authentication methods, including password and keyboard-interactive callbacks. In applications that misuse the Se…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
6.8 → 9.1
medium → critical
9.1 → 6.8
critical → medium
6.8 → 9.1
medium → critical
9.1 → 6.8
critical → medium
6.8 → 9.1
medium → critical
9.1 → 6.8
critical → medium
Last analysed / modified upstream
A flaw was found in golang.org/x/crypto/ssh. The component failed to properly enforce source-address restrictions for several authentication methods, including password and keyboard-interactive callbacks. In applications that misuse the ServerConfig.PublicKeyCallback callback to make security relevant authorization decisions, an attacker with a valid key could bypass network-based access controls to gain additional privileges.
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions — rated Important by Red Hat. Released 2026-08-28, updated 2026-09-23.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68333 It is recommended that existing users of Red Hat OpenShift Builds 1.8.z upgrade to 1.8.2 https://access.redhat.com/errata/RHSA-2026:69945 It is recommended that existing users of Red Hat OpenShift Builds 1.9.0 upgrade to 1.9.1 https://access.redhat.com/errata/RHSA-2026:69925
Workarounds / mitigations:
Affected packages:
golang.org/x/crypto < 0.55.0Patched in:
golang.org/x/crypto 0.55.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71556High· 7.1go-git is an extensible git implementation library written in pure Go
CVE-2021-33194High· 7.5golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)
CVE-2022-23526High· 7.5helm: Denial of service through schema file (CVE-2022-23526)
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)
CVE-2026-56855Medium· 5.3golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages (CVE-2026-56855)
CVE-2026-78662Medium· 5.3golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding (CVE-2026-78662)