CVE-2026-39832
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
9.1
CRITICAL
CVSS 3.1
EPSS 0.53%
描述
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
如何修補 CVE-2026-39832
要修補 CVE-2026-39832,請將受影響套件升級到下列已修補版本。
- —升級至 0.52.0 或更新版本
- —升級至 0.52.0 或更新版本
CVE-2026-39832 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.52.0
- from 0, < 0.52.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |