Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39832

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 8.7
EPSS Низкий

Описание

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

A flaw was found in golang.org/x/crypto/ssh/agent. When a key was added to a remote agent, security restrictions, known as constraint extensions, were not properly processed during the request. This allowed these restrictions to be silently removed when keys were forwarded, leading to the unrestricted use of the key on the remote host. This vulnerability could enable an attacker to bypass intended security controls and perform unauthorized actions.

Отчет

This Important vulnerability in golang.org/x/crypto/ssh/agent allows for a security bypass when SSH keys with destination restrictions are forwarded via an SSH agent. This flaw could lead to unintended exposure of SSH keys, enabling an attacker to use the forwarded key without the specified restrictions on remote hosts. Red Hat products utilizing golang.org/x/crypto/ssh/agent for key forwarding may be affected if users rely on constraint extensions for limiting key usage.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Will not fix
Multicluster Engine for Kubernetesmulticluster-engine/cluster-image-set-controller-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/hypershift-addon-rhel9-operatorUnder investigation
OpenShift Pipelinesopenshift-pipelines-clientAffected
OpenShift Serverlessopenshift-serverless-1/kn-plugin-func-func-util-rhel9Affected
OpenShift Serverlessopenshift-serverless-clientsAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-operators-subscription-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Will not fix
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-281
https://bugzilla.redhat.com/show_bug.cgi?id=2480685golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions

EPSS

Процентиль: 45%
0.006
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

CVSS3: 9.1
nvd
2 месяца назад

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

CVSS3: 9.1
msrc
2 месяца назад

Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent

CVSS3: 9.1
debian
2 месяца назад

When adding a key to a remote agent constraint extensions such as rest ...

CVSS3: 8.7
redos
22 дня назад

Уязвимость portainer-ce

EPSS

Процентиль: 45%
0.006
Низкий

8.7 High

CVSS3

Уязвимость CVE-2026-39832