Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

CVE-2025-58181: OpenSSH servers can run out of memory from malicious authentication requests

GHSA-j5w8-q4qc-rx2x CVE-2025-58181 GHSA-j5w8-q4qc-rx2x CVE-2025-58181 GO-2025-4134
Summary

OpenSSH servers may crash or become unresponsive if a malicious user sends an excessive number of authentication requests. This could allow an attacker to disrupt the server's ability to authenticate legitimate users. Update your OpenSSH server to the latest version to fix this issue.

What to do
  • Update golang.org x to version 0.45.0.
  • Update x golang.org/x/crypto to version 0.45.0.
Affected software
Ecosystem VendorProductAffected versions
go golang.org x < 0.45.0
Fix: upgrade to 0.45.0
– golang crypto < 0.45.0
cpe:2.3:a:golang:crypto:*:*:*:*:*:go:*:*
Go x golang.org/x/crypto < 0.45.0
Fix: upgrade to 0.45.0
Original title
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
Original description
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
ghsa CVSS3.1 5.3
Vulnerability type
CWE-770 Allocation of Resources Without Limits
Published: 19 Nov 2025 · Updated: 17 Jul 2026 · First seen: 6 Mar 2026