Количество 71
Количество 71
CVE-2026-39829
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.
CVE-2026-39829
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.
CVE-2026-39829
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.
CVE-2026-39829
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
CVE-2026-39829
The RSA and DSA public key parsers did not enforce size limits on key ...
GHSA-w879-237q-wc7r
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
BDU:2026-07495
Уязвимость пакета golang.org/x/crypto/ssh библиотеки для языка программирования Go crypto, позволяющая нарушителю вызвать отказ в обслуживании
RLSA-2026:37410
Important: buildah security update
ELSA-2026-37410
ELSA-2026-37410: buildah security update (IMPORTANT)
CVE-2026-39830
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVE-2026-39830
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVE-2026-39830
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVE-2026-39830
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
CVE-2026-39830
A malicious SSH peer could send unsolicited global request responses t ...
ROS-20260709-73-0025
Уязвимость portainer-ce
GHSA-vgwf-h737-ff37
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-39829 The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-39829 The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-39829 The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-39829 Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-39829 The RSA and DSA public key parsers did not enforce size limits on key ... | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-w879-237q-wc7r golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
BDU:2026-07495 Уязвимость пакета golang.org/x/crypto/ssh библиотеки для языка программирования Go crypto, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
RLSA-2026:37410 Important: buildah security update | 21 день назад | |||
ELSA-2026-37410 ELSA-2026-37410: buildah security update (IMPORTANT) | 21 день назад | |||
CVE-2026-39830 A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded. | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-39830 A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-39830 A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded. | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-39830 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
CVE-2026-39830 A malicious SSH peer could send unsolicited global request responses t ... | CVSS3: 9.1 | 1% Низкий | 2 месяца назад | |
ROS-20260709-73-0025 Уязвимость portainer-ce | CVSS3: 7.5 | 1% Низкий | 22 дня назад | |
GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | CVSS3: 9.1 | 1% Низкий | около 1 месяца назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | CVSS3: 5.3 | 1% Низкий | 2 месяца назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | CVSS3: 5.3 | 1% Низкий | 2 месяца назад | |
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | CVSS3: 5.3 | 1% Низкий | 2 месяца назад |
Уязвимостей на страницу