Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46595

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

A flaw was found in golang.org/x/crypto/ssh. Source-address validation can be skipped when an SSH server configuration uses an authentication callback type other than public key, allowing authorization bypass in misconfigured servers. This is a follow-on to incomplete coverage from the CVE-2024-45337 fix.

Отчет

golang.org/x/crypto/ssh is vulnerable to authorization bypass when SSH server configurations rely on source-address validation alongside non-public-key authentication callbacks. An attacker with low privileges who can authenticate through such a callback path may bypass intended source-address restrictions and gain unauthorized SSH access. Red Hat impact sits in services built with affected x/crypto/ssh, including RHEL golang streams, hummingbird Go toolchains, RHACM/MCE agents, and OpenShift or Ceph components that embed Go SSH servers with mixed callback types.

Меры по смягчению последствий

Upgrade to a fixed golang.org/x/crypto/ssh release via updated golang or package rebuilds. Ensure SSH servers use supported public-key callback configurations with source-address validation as intended.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorAffected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Will not fix
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-8-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/backplane-rhel9-operatorAffected
Multicluster Engine for Kubernetesmulticluster-engine/cluster-image-set-controller-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/hypershift-addon-rhel9-operatorUnder investigation
Multicluster Engine for Kubernetesmulticluster-engine/managedcluster-import-controllerAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-303
https://bugzilla.redhat.com/show_bug.cgi?id=2480689golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation

EPSS

Процентиль: 40%
0.00503
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 10
ubuntu
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

CVSS3: 10
nvd
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

msrc
2 месяца назад

Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh

CVSS3: 10
debian
2 месяца назад

Previously, CVE-2024-45337 fixed an authorization bypass for misused s ...

CVSS3: 7.1
redos
20 дней назад

Уязвимость portainer-ce

EPSS

Процентиль: 40%
0.00503
Низкий

7.1 High

CVSS3