Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

github логотип

GHSA-gjhq-gjfw-99mq

24 дня назад

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-56854

24 дня назад

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-56854

25 дней назад

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-56854

24 дня назад

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-56854

24 дня назад

The source-address critical option in the Permissions returned by an a ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21861-1

6 дней назад

Security update for gh

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21846-1

8 дней назад

Security update for keybase-client

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21814-1

14 дней назад

Security update for zk

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21835-1

8 дней назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21816-1

13 дней назад

Security update for hauler

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21841-1

8 дней назад

Security update for hauler

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21801-1

15 дней назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4209-1

6 дней назад

Security update for containerized-data-importer

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21824-1

13 дней назад

Security update for containerized-data-importer1.65

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gjhq-gjfw-99mq

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.

CVSS3: 7.5
0%
Низкий
24 дня назад
ubuntu логотип
CVE-2026-56854

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.

CVSS3: 7.5
0%
Низкий
24 дня назад
redhat логотип
CVE-2026-56854

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.

CVSS3: 6.8
0%
Низкий
25 дней назад
nvd логотип
CVE-2026-56854

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.

CVSS3: 7.5
0%
Низкий
24 дня назад
debian логотип
CVE-2026-56854

The source-address critical option in the Permissions returned by an a ...

CVSS3: 7.5
0%
Низкий
24 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21861-1

Security update for gh

6 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21846-1

Security update for keybase-client

8 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21814-1

Security update for zk

14 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21835-1

Security update for trivy

8 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21816-1

Security update for hauler

13 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21841-1

Security update for hauler

8 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21801-1

Security update for trivy

15 дней назад
suse-cvrf логотип
SUSE-SU-2026:4209-1

Security update for containerized-data-importer

6 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21824-1

Security update for containerized-data-importer1.65

13 дней назад

Уязвимостей на страницу