Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32952

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using ntlmssp.Negotiator as an HTTP transport. Version 0.1.1 patches the issue.

A flaw was found in the go-ntlmssp package (before 0.1.1). A remote attacker can send a crafted NTLM challenge message that triggers a slice out-of-bounds panic, crashing any Go process using ntlmssp.Negotiator as an HTTP transport.

Отчет

go-ntlmssp is vulnerable to denial of service in NTLM challenge parsing before version 0.1.1. When a Go process uses ntlmssp.Negotiator as an HTTP transport, a remote party can send a malformed NTLM challenge that triggers a slice out-of-bounds panic and crashes the process. Red Hat exposure is narrow: most products that transitively bundle the library (OpenShift must-gather images, CNV must-gather, cert-manager, Ceph dashboard, Ansible Automation Platform utilities) are not affected because they do not use Negotiator against untrusted NTLM endpoints; the remaining risk sits with any Go service that authenticates over HTTP via NTLM/Negotiate and accepts challenge messages from an attacker-influenced source.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Under investigation
cert-manager Operator for Red Hat OpenShiftcert-manager/cert-manager-istio-csr-rhel9Not affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-acmesolver-rhel9Not affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-must-gather-rhel9Under investigation
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Not affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-bundleNot affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-rhel9Not affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Not affected
Kernel Module Management Operator for Red Hat Openshiftkmm/kernel-module-management-must-gather-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2461375go-ntlmssp: go-ntlmssp: Denial of Service via malicious NTLM challenge

EPSS

Процентиль: 60%
0.01027
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue.

CVSS3: 5.3
nvd
4 месяца назад

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue.

CVSS3: 5.3
debian
4 месяца назад

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication ...

CVSS3: 5.3
github
4 месяца назад

go-ntlmssp NTLM challenges can panic on malformed payloads

suse-cvrf
21 день назад

Security update for rclone

EPSS

Процентиль: 60%
0.01027
Низкий

5.3 Medium

CVSS3