CVE-2026-39830
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
9.1
CRITICAL
CVSS 3.1
EPSS 0.53%
描述
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
如何修補 CVE-2026-39830
要修補 CVE-2026-39830,請將受影響套件升級到下列已修補版本。
- —升級至 0.52.0 或更新版本
- —升級至 0.52.0 或更新版本
CVE-2026-39830 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.52.0
- from 0, < 0.52.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |