Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 71

Количество 71

ubuntu логотип

CVE-2026-39829

2 месяца назад

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-39829

2 месяца назад

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-39829

2 месяца назад

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-39829

2 месяца назад

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-39829

2 месяца назад

The RSA and DSA public key parsers did not enforce size limits on key ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w879-237q-wc7r

около 1 месяца назад

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-07495

2 месяца назад

Уязвимость пакета golang.org/x/crypto/ssh библиотеки для языка программирования Go crypto, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:37410

21 день назад

Important: buildah security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-37410

21 день назад

ELSA-2026-37410: buildah security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-39830

2 месяца назад

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-39830

2 месяца назад

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-39830

2 месяца назад

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2026-39830

2 месяца назад

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-39830

2 месяца назад

A malicious SSH peer could send unsolicited global request responses t ...

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260709-73-0025

22 дня назад

Уязвимость portainer-ce

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vgwf-h737-ff37

около 1 месяца назад

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2026-39835

2 месяца назад

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-39835

2 месяца назад

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-39835

2 месяца назад

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-39835

2 месяца назад

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-39829

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

CVSS3: 7.5
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-39829

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-39829

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

CVSS3: 7.5
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-39829

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

CVSS3: 7.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-39829

The RSA and DSA public key parsers did not enforce size limits on key ...

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-w879-237q-wc7r

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-07495

Уязвимость пакета golang.org/x/crypto/ssh библиотеки для языка программирования Go crypto, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:37410

Important: buildah security update

21 день назад
oracle-oval логотип
ELSA-2026-37410

ELSA-2026-37410: buildah security update (IMPORTANT)

21 день назад
ubuntu логотип
CVE-2026-39830

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 9.1
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-39830

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-39830

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 9.1
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-39830

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

CVSS3: 9.1
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-39830

A malicious SSH peer could send unsolicited global request responses t ...

CVSS3: 9.1
1%
Низкий
2 месяца назад
redos логотип
ROS-20260709-73-0025

Уязвимость portainer-ce

CVSS3: 7.5
1%
Низкий
22 дня назад
github логотип
GHSA-vgwf-h737-ff37

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

CVSS3: 9.1
1%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

CVSS3: 5.3
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-39835

Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh

CVSS3: 5.3
1%
Низкий
2 месяца назад

Уязвимостей на страницу