CVE-2026-78662Medium· 5.3▾ SunlitA flaw was found in golang.org/x/crypto/ssh. A malicious remote attacker could flood a channel's incoming requests before it is established, leading to a deadlock of the entire connection. This could result in a denial of service (DoS) for…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.3%
Last analysed / modified upstream
5.3 → —
medium → none
— → 5.3
none → medium
5.3 → —
medium → none
— → 5.3
none → medium
5.3 → —
medium → none
— → 5.3
none → medium
A flaw was found in golang.org/x/crypto/ssh. A malicious remote attacker could flood a channel's incoming requests before it is established, leading to a deadlock of the entire connection. This could result in a denial of service (DoS) for legitimate users.
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding — rated Moderate by Red Hat. Released 2026-09-02, updated 2026-09-12.
Affected:
No fix planned:
Out of support scope
Workarounds / mitigations:
Affected packages:
golang.org/x/crypto < 0.56.0Patched in:
golang.org/x/crypto 0.56.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56855Medium· 5.3golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages (CVE-2026-56855)
CVE-2026-89732Medium· 5.5kernel: usb: gadget: f_fs: Prevent deadlock during ep0 read loop (CVE-2026-89732)
CVE-2021-33194High· 7.5golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)
CVE-2022-23526High· 7.5helm: Denial of service through schema file (CVE-2022-23526)
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)
CVE-2026-56854Medium· 6.8golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854)