Google Go是美国谷歌(Google)公司的一种静态强类型、编译型、并发型,并具有垃圾回收功能的编程语言。 Google Go存在安全漏洞,该漏洞源于通过强制转换格式错误的线缆字节创建ed25519.PrivateKey,可能导致使用时发生崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| golang.org/x/crypto | golang.org/x/crypto/ssh/agent | < 0.52.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| golang.org/x/crypto | golang.org/x/crypto/ssh/agent | 0 ~ 0.52.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42508 | Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts | |
| CVE-2026-39829 | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh | |
| CVE-2026-39835 | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | |
| CVE-2026-39831 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh | |
| CVE-2026-39833 | Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent | |
| CVE-2026-39834 | Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh | |
| CVE-2026-39830 | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ | |
| CVE-2026-39828 | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh | |
| CVE-2026-39827 | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh | |
| CVE-2026-39832 | Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent | |
| CVE-2026-46597 | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh | |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ss |
No comments yet