CVE-2026-56855Medium· 5.3▾ SunlitA flaw was found in golang.org/x/crypto/ssh. After a channel has been established, a remote malicious peer could send specially crafted messages. This could lead to a deadlock of the entire connection, resulting in a Denial of Service (DoS…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.4%
Last analysed / modified upstream
5.3 → —
medium → none
— → 5.3
none → medium
5.3 → —
medium → none
— → 5.3
none → medium
5.3 → —
medium → none
— → 5.3
none → medium
A flaw was found in golang.org/x/crypto/ssh. After a channel has been established, a remote malicious peer could send specially crafted messages. This could lead to a deadlock of the entire connection, resulting in a Denial of Service (DoS) for the affected system.
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages — rated Moderate by Red Hat. Released 2026-09-02, updated 2026-09-14.
Affected:
No fix planned:
Fix deferred
Workarounds / mitigations:
Affected packages:
golang.org/x/crypto < 0.56.0Patched in:
golang.org/x/crypto 0.56.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-78662Medium· 5.3golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding (CVE-2026-78662)
CVE-2026-89732Medium· 4.1kernel: Kernel: USB FunctionFS deadlock via ep0 read loop (CVE-2026-89732)
CVE-2021-33194High· 7.5golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)
CVE-2022-23526High· 7.5helm: Denial of service through schema file (CVE-2022-23526)
CVE-2026-39823Medium· 5.4html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823)
CVE-2026-39826Medium· 5.4html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)