← Vulnerability feed

Vulnerability record · CVE-2026-46595 · published 22 May 2026

CVE-2026-46595: Golang crypto incorrect authorization vulnerability

Golang · Crypto

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

10.0 CVSS 3.1 Critical EPSS 0.60% · top 53.3% CWE-863 · Incorrect authorizationCWE-303 · CWE-303
10.0CVSS 3.1 base score
0.60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References
11 Sep 2026Last modified by NVD

Description

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://go.dev/cl/781642 Issue Tracking
https://go.dev/issue/79570 Issue Tracking
https://groups.google.com/g/golang-announce/c/a082jnz-LvI Mailing List
https://pkg.go.dev/vuln/GO-2026-5023 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:23262
https://access.redhat.com/errata/RHSA-2026:23264
https://access.redhat.com/errata/RHSA-2026:26546
https://access.redhat.com/errata/RHSA-2026:26547
https://access.redhat.com/errata/RHSA-2026:30650
https://access.redhat.com/errata/RHSA-2026:30651
https://access.redhat.com/errata/RHSA-2026:33524
https://access.redhat.com/errata/RHSA-2026:33531
https://access.redhat.com/errata/RHSA-2026:36207
https://access.redhat.com/errata/RHSA-2026:36648
https://access.redhat.com/errata/RHSA-2026:36651
https://access.redhat.com/errata/RHSA-2026:36796
https://access.redhat.com/errata/RHSA-2026:36797
https://access.redhat.com/errata/RHSA-2026:36808
https://access.redhat.com/errata/RHSA-2026:36820
https://access.redhat.com/errata/RHSA-2026:37275
https://access.redhat.com/errata/RHSA-2026:37387
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:41019
https://access.redhat.com/errata/RHSA-2026:41036
https://access.redhat.com/errata/RHSA-2026:42796
https://access.redhat.com/errata/RHSA-2026:43692
https://access.redhat.com/errata/RHSA-2026:47737
https://access.redhat.com/errata/RHSA-2026:48151
https://access.redhat.com/errata/RHSA-2026:51033
https://access.redhat.com/errata/RHSA-2026:54531
https://access.redhat.com/errata/RHSA-2026:59467
https://access.redhat.com/errata/RHSA-2026:59558
https://access.redhat.com/errata/RHSA-2026:60520
https://access.redhat.com/errata/RHSA-2026:61314
https://access.redhat.com/errata/RHSA-2026:66022
https://access.redhat.com/errata/RHSA-2026:66521
https://access.redhat.com/security/cve/CVE-2026-46595
https://bugzilla.redhat.com/show_bug.cgi?id=2480689
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json

Track CVE-2026-46595 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-42508Golang crypto improper certificate validation vulnerabilityPreviously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are check…EPSS 0.65%9.1CVE-2026-39834Golang crypto integer overflow vulnerabilityWhen writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the w…EPSS 0.64%9.1CVE-2026-39830Golang crypto memory buffer overflow vulnerabilityA malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked gor…EPSS 0.62%9.1CVE-2026-39831Golang crypto missing authorization vulnerabilityThe Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence …EPSS 0.49%9.1CVE-2026-39832Golang crypto deserialization of untrusted data vulnerabilityWhen adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destinatio…EPSS 0.72%9.1CVE-2026-39833Golang crypto missing authorization vulnerabilityThe in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign …EPSS 0.49%8.1CVE-2017-3204Golang crypto vulnerabilityThe Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4…EPSS 3.2%7.5CVE-2026-78662Golang crypto allocation without limits vulnerabilityPreviously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingR…EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2026-46595), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.