Количество 82
Количество 82
GHSA-vgwf-h737-ff37
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
BDU:2026-12028
Уязвимость функции Close() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260831-80-0009
Уязвимость prometheus-podman-exporter
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
CVE-2026-39835
SSH servers which use CertChecker as a public key callback without set ...
CVE-2026-39832
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
CVE-2026-39832
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
CVE-2026-39832
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
CVE-2026-39832
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
CVE-2026-39832
When adding a key to a remote agent constraint extensions such as rest ...
ROS-20260901-80-0026
Уязвимость prometheus-podman-exporter
GHSA-78mq-xcr3-xm33
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
ROS-20260709-80-0028
Уязвимость portainer-ce
ROS-20260709-73-0027
Уязвимость portainer-ce
GHSA-f5wc-c3c7-36mc
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
BDU:2026-12029
Уязвимость функции NewKeyring() языка программирования Go, позволяющая нарушителю повысить свои привилегии
ROS-20260831-80-0011
Уязвимость prometheus-podman-exporter
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
BDU:2026-12028 Уязвимость функции Close() языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
ROS-20260831-80-0009 Уязвимость prometheus-podman-exporter | CVSS3: 7.5 | 1% Низкий | 14 дней назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | CVSS3: 5.3 | 1% Низкий | 4 месяца назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil. | CVSS3: 5.3 | 1% Низкий | 4 месяца назад | |
CVE-2026-39835 Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | CVSS3: 5.3 | 1% Низкий | 4 месяца назад | |
CVE-2026-39835 SSH servers which use CertChecker as a public key callback without set ... | CVSS3: 5.3 | 1% Низкий | 4 месяца назад | |
CVE-2026-39832 When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them. | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-39832 When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them. | CVSS3: 8.7 | 1% Низкий | 4 месяца назад | |
CVE-2026-39832 When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them. | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-39832 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-39832 When adding a key to a remote agent constraint extensions such as rest ... | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
ROS-20260901-80-0026 Уязвимость prometheus-podman-exporter | CVSS3: 7.5 | 1% Низкий | 13 дней назад | |
GHSA-78mq-xcr3-xm33 golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow | CVSS3: 5.3 | 1% Низкий | 3 месяца назад | |
ROS-20260709-80-0028 Уязвимость portainer-ce | CVSS3: 8.7 | 1% Низкий | 2 месяца назад | |
ROS-20260709-73-0027 Уязвимость portainer-ce | CVSS3: 8.7 | 1% Низкий | 2 месяца назад | |
GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
BDU:2026-12029 Уязвимость функции NewKeyring() языка программирования Go, позволяющая нарушителю повысить свои привилегии | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
ROS-20260831-80-0011 Уязвимость prometheus-podman-exporter | CVSS3: 9.1 | 1% Низкий | 14 дней назад |
Уязвимостей на страницу