Auth Bypass in golang.org/x/crypto/ssh <0.52.0
CVE-2026-46595 Published on May 22, 2026
Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
Vulnerability Analysis
CVE-2026-46595 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.
Weakness Types
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-46595 has been classified to as an AuthZ vulnerability or weakness.
Incorrect Implementation of Authentication Algorithm
The requirements for the software dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect. This incorrect implementation may allow authentication to be bypassed.
Products Associated with CVE-2026-46595
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-46595 are published in these products:
Affected Versions
golang.org/x/crypto/ssh:- Before 0.52.0 is affected.
- Version 4.2.0-19 and below * is unaffected.
- Version 0:1.0.3-1.el9em and below * is unaffected.
- Version 0:1.1.3-1.el10em and below * is unaffected.
- Version 0:1.1.3-1.el9em and below * is unaffected.
- Version 1782401674 and below * is unaffected.
- Version 1782160196 and below * is unaffected.
- Version 1782477094 and below * is unaffected.
- Version 1782160009 and below * is unaffected.
- Version 1782160210 and below * is unaffected.
- Version 1782160541 and below * is unaffected.
- Version 1782159773 and below * is unaffected.
- Version 1784058822 and below * is unaffected.
- Version 1782383730 and below * is unaffected.
- Version 1782488873 and below * is unaffected.
- Version 1782382711 and below * is unaffected.
- Version 1784652040 and below * is unaffected.
- Version 1784638644 and below * is unaffected.
- Version 1781686446 and below * is unaffected.
- Version 1781686458 and below * is unaffected.
- Version 1783352589 and below * is unaffected.
- Version 1783502025 and below * is unaffected.
- Version 1784196588 and below * is unaffected.
- Version 1784126780 and below * is unaffected.
- Version 1782804957 and below * is unaffected.
- Version 1782758407 and below * is unaffected.
- Version 1782758410 and below * is unaffected.
- Version 1782754093 and below * is unaffected.
- Version 1782744816 and below * is unaffected.
- Version 1782758409 and below * is unaffected.
- Version 1782744830 and below * is unaffected.
- Version 1.25.11-2.hum1 and below * is unaffected.
- Version 1.26.4-2.hum1 and below * is unaffected.
- Version 1782471656 and below * is unaffected.
- Version 1783057868 and below * is unaffected.
- Version 1784121108 and below * is unaffected.
- Version 1783612119 and below * is unaffected.
- Version 1782932114 and below * is unaffected.
- Version 1782931768 and below * is unaffected.
- Version 1782932104 and below * is unaffected.
- Version 1783536000 and below * is unaffected.
- Version 1783535989 and below * is unaffected.
- Version 1783536515 and below * is unaffected.
- Version 1782932521 and below * is unaffected.
- Version 1783018461 and below * is unaffected.
- Version 1783018421 and below * is unaffected.
- Version 1782932812 and below * is unaffected.
- Version 1783537001 and below * is unaffected.
- Version 1782932919 and below * is unaffected.
- Version 1783537586 and below * is unaffected.
- Version 1782932969 and below * is unaffected.
- Version 1782933015 and below * is unaffected.
- Version 1782933042 and below * is unaffected.
- Version 1783537392 and below * is unaffected.
- Version 1782933235 and below * is unaffected.
- Version 1782933251 and below * is unaffected.
- Version 1783537955 and below * is unaffected.
- Version 1782933417 and below * is unaffected.
- Version 1783537742 and below * is unaffected.
- Version 1782933602 and below * is unaffected.
- Version 1783019377 and below * is unaffected.
- Version 1782934054 and below * is unaffected.
- Version 1782934036 and below * is unaffected.
- Version 1782934284 and below * is unaffected.
- Version 1782403274 and below * is unaffected.
- Version 1784351966 and below * is unaffected.
- Version 4-1.4.2 and below * is unaffected.
- Version 4-1.4.3 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.