CVE-2026-46595
CVE-2026-46595 is a critical authorization flaw in the Go programming language's crypto package, related to SSH server configurations. It stems from a previously patched issue where source-address validation could be skipped if a non-public-key callback was used, and the new CVE indicates the underlying problem remains or recurs.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Applications or services using the Go (Golang) crypto package for SSH server functionality, particularly those with configurations involving non-public-key callbacks.
Real-world impact
An attacker could potentially bypass authorization controls on affected SSH servers built with the vulnerable Go crypto package, allowing unauthorized access depending on how the server is configured.
Why this severity
CVSS score 10 out of 10 (critical): the flaw is exploitable over a network with no privileges or user interaction required, and can lead to a full loss of confidentiality and integrity.
What to do about it
- ›No official fix is documented in the provided sources. Until a patch is released, review SSH server configurations using the Go crypto package and avoid passing non-public-key callbacks that could skip source-address validation.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 22, 2026 · May 22, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 7h agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- go.dev/cl/781642issue tracking
- go.dev/issue/79570issue tracking
- groups.google.com/g/golang-announce/c/a082jnz…mailing list
- pkg.go.dev/vuln/GO-2026-5023vendor advisory
- access.redhat.com/errata/RHSA-2026:23262
- access.redhat.com/errata/RHSA-2026:23264
- access.redhat.com/errata/RHSA-2026:26546
- access.redhat.com/errata/RHSA-2026:26547
- access.redhat.com/errata/RHSA-2026:30650
- access.redhat.com/errata/RHSA-2026:30651
- access.redhat.com/errata/RHSA-2026:33524
- access.redhat.com/errata/RHSA-2026:33531
- access.redhat.com/errata/RHSA-2026:36207
- access.redhat.com/errata/RHSA-2026:36648
- access.redhat.com/errata/RHSA-2026:36651
- access.redhat.com/errata/RHSA-2026:36796
- access.redhat.com/errata/RHSA-2026:36797
- access.redhat.com/errata/RHSA-2026:36808
- access.redhat.com/errata/RHSA-2026:36820
- access.redhat.com/errata/RHSA-2026:37275