← Back to browse · API

CVE-2026-46595

Severity
CRITICAL
CVSS
10.0
EPSS
0.00503
Risk score
40.18
CISA KEV
No
PoC
Yes
Published
2026-05-22
Modified
2026-08-14
First seen
2026-08-05
Aliases
EUVD-2026-31398, GHSA-X527-X647-Q7GG
Products
golang.org/x/crypto:golang.org/x/crypto/ssh 0 <0.52.0, golang:crypto, linux, suse, ubuntu
Sources
nvd CVE-2026-46595
packetstorm 00d9139cc1f660272356ea09|CVE-2026-46595
packetstorm 63600a2e2888a5c33344d69c|CVE-2026-46595
packetstorm 3a8d17efc6dd1f99782375cd|CVE-2026-46595
packetstorm 2a1d19bd1898ed344c9a0fb0|CVE-2026-46595
packetstorm 52010ad09faf7d5aa45e29e4|CVE-2026-46595
packetstorm a6a89daa81844a52cc8b1084|CVE-2026-46595
packetstorm bc44d953b7f74e42f27e941c|CVE-2026-46595
packetstorm bf0ae59e5a12ecf7ef501e40|CVE-2026-46595
packetstorm 2b7be0527e64aaddcf7cc3f5|CVE-2026-46595
packetstorm e760ebd193aaec6c0d4acb9c|CVE-2026-46595
packetstorm f6c1d3c51043a88ab7caad9f|CVE-2026-46595
packetstorm c5ff857a1740331388574741|CVE-2026-46595
packetstorm 9a3837e40220349d37b98257|CVE-2026-46595
packetstorm a6054e43a35528da48395c5f|CVE-2026-46595
euvd EUVD-2026-31398
packetstorm 4a625c0a455d96dbc9e6257e|CVE-2026-46595
packetstorm 9d39e484078300c1498e1881|CVE-2026-46595
packetstorm 0413d0d675142b500cbd6cc5|CVE-2026-46595
packetstorm bc0ca11275af840993a9cb4a|CVE-2026-46595
packetstorm 136992d08a2a5eddf41de786|CVE-2026-46595
packetstorm 7fbe927fbac6af9cc74a5692|CVE-2026-46595
packetstorm 8a18982980d6d80637f5013e|CVE-2026-46595
packetstorm f7fba5109000c38cef03c8ae|CVE-2026-46595
packetstorm c09cf7dec373fb0af30cd49e|CVE-2026-46595
packetstorm d6a3396e47f7a84681296d27|CVE-2026-46595

Description

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

References