Vulnerabilities
Vulnerable Software
Golang:  >> Crypto  >> 0.48.0  Security Vulnerabilities
An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-05-22
The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.
CVSS Score
8.1
EPSS Score
0.032
Published
2017-04-04


Contact Us

Shodan ® - All rights reserved