CVE-2026-39830
A flaw in Go’s crypto SSH library allowed a malicious SSH peer to send unsolicited global request responses that could fill an internal buffer and block the connection’s read loop, causing a resource leak. The issue has been fixed by discarding such unsolicited responses.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
The vulnerability affects the golang crypto SSH library used in Go applications that establish SSH connections.
Real-world impact
An attacker could send crafted SSH messages to a target system, exhausting its resources and potentially causing a denial‑of‑service by preventing the application from processing legitimate traffic.
Why this severity
The CVSS score of 9.1 reflects a network‑based attack that requires no privileges or user interaction, has low complexity, and can completely deny availability while also compromising confidentiality.
What to do about it
- 01Upgrade your Go installation to the latest release that includes the golang crypto SSH library fix.
NVD-referenced vendor advisory
Timeline
- May 22, 2026 · May 22, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 17d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Aug 4, 2026 · 7h agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- go.dev/cl/781640issue tracking
- go.dev/cl/781664issue tracking
- go.dev/issue/79564issue tracking
- groups.google.com/g/golang-announce/c/a082jnz…mailing list
- pkg.go.dev/vuln/GO-2026-5017vendor advisory
- access.redhat.com/errata/RHSA-2026:29455
- access.redhat.com/errata/RHSA-2026:35833
- access.redhat.com/errata/RHSA-2026:36199
- access.redhat.com/errata/RHSA-2026:36207
- access.redhat.com/errata/RHSA-2026:36319
- access.redhat.com/errata/RHSA-2026:36625
- access.redhat.com/errata/RHSA-2026:36648
- access.redhat.com/errata/RHSA-2026:36651
- access.redhat.com/errata/RHSA-2026:36796
- access.redhat.com/errata/RHSA-2026:36797
- access.redhat.com/errata/RHSA-2026:36808
- access.redhat.com/errata/RHSA-2026:37072
- access.redhat.com/errata/RHSA-2026:37268
- access.redhat.com/errata/RHSA-2026:37271
- access.redhat.com/errata/RHSA-2026:37272