Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-46595: Go SSH Server Skips Security Checks for Wrong Authentication

CVE-2026-46595 · published today
Summary

A security check is bypassed in Go SSH servers when using an incorrect authentication method. This allows unauthorized access to the server. To fix this, update your Go SSH server to the latest version.

What to do
  • Update x golang.org/x/crypto to version 0.52.0.
  • Update golang.org x to version 0.52.0.
  • Update canonical google-guest-agent to version 20250116.00-0ubuntu1~24.04.4.
  • Update canonical google-guest-agent to version 20250506.01-0ubuntu1.2.
  • Update canonical google-guest-agent to version 20250506.01-0ubuntu2.1.
  • Update canonical golang-go.crypto to version 1:0.47.0-1ubuntu0.1~esm1.
  • Update debian golang-go.crypto to version 1:0.52.0-1.
  • Update x golang.org/x/crypto to version v0.32.0-aikido.3.
  • Update x rootio-golang.org/x/crypto to version v0.32.0-root.io.3.
  • Update x golang.org/x/crypto to version v0.32.0-aikido.5.
  • Update x rootio-golang.org/x/crypto to version v0.32.0-root.io.5.
  • Update x golang.org/x/crypto to version v0.32.0-aikido.4.
  • Update x rootio-golang.org/x/crypto to version v0.32.0-root.io.4.
  • Update golang crypto to version 0.52.0 or later.
  • Update golang.org/x/crypto golang.org/x/crypto/ssh to version 0.52.0 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:20.04:LTS canonical golang-go.crypto All versions
Ubuntu:22.04:LTS canonical google-guest-agent All versions
Ubuntu:22.04:LTS canonical snapd All versions
Ubuntu:Pro:22.04:LTS canonical golang-go.crypto All versions
Ubuntu:24.04:LTS canonical google-guest-agent < 20250116.00-0ubuntu1~24.04.4
Fix: upgrade to 20250116.00-0ubuntu1~24.04.4
Ubuntu:24.04:LTS canonical snapd All versions
Ubuntu:Pro:24.04:LTS canonical golang-go.crypto All versions
Ubuntu:25.10 canonical golang-go.crypto All versions
Ubuntu:25.10 canonical google-guest-agent < 20250506.01-0ubuntu1.2
Fix: upgrade to 20250506.01-0ubuntu1.2
Ubuntu:25.10 canonical snapd All versions
Ubuntu:26.04:LTS canonical golang-go.crypto All versions
Ubuntu:26.04:LTS canonical google-guest-agent < 20250506.01-0ubuntu2.1
Fix: upgrade to 20250506.01-0ubuntu2.1
Ubuntu:26.04:LTS canonical snapd All versions
Go x golang.org/x/crypto < 0.52.0
Fix: upgrade to 0.52.0
Debian:11 debian golang-go.crypto All versions
Debian:12 debian golang-go.crypto All versions
Debian:13 debian golang-go.crypto All versions
Debian:14 debian golang-go.crypto < 1:0.52.0-1
Fix: upgrade to 1:0.52.0-1
Ubuntu:Pro:16.04:LTS canonical golang-go.crypto All versions
Ubuntu:Pro:16.04:LTS canonical lxd All versions
Ubuntu:Pro:16.04:LTS canonical snapd All versions
Ubuntu:Pro:16.04:LTS canonical google-guest-agent All versions
Ubuntu:Pro:18.04:LTS canonical lxd All versions
Ubuntu:Pro:18.04:LTS canonical snapd All versions
Ubuntu:Pro:18.04:LTS canonical golang-go.crypto All versions
Ubuntu:Pro:18.04:LTS canonical google-guest-agent All versions
Ubuntu:Pro:20.04:LTS canonical google-guest-agent All versions
Ubuntu:Pro:20.04:LTS canonical snapd All versions
golang crypto < 0.52.0
cpe:2.3:a:golang:crypto:*:*:*:*:*:go:*:*
go golang.org x < 0.52.0
Fix: upgrade to 0.52.0
golang.org/x/crypto golang.org/x/crypto/ssh < 0.52.0
Ubuntu:Pro:26.04:LTS canonical golang-go.crypto < 1:0.47.0-1ubuntu0.1~esm1
Fix: upgrade to 1:0.47.0-1ubuntu0.1~esm1
Root:Go x golang.org/x/crypto < v0.32.0-aikido.3
< v0.32.0-aikido.5
< v0.32.0-aikido.4
Fix: upgrade to v0.32.0-aikido.3
Root:Go x rootio-golang.org/x/crypto < v0.32.0-root.io.3
< v0.32.0-root.io.5
< v0.32.0-root.io.4
Fix: upgrade to v0.32.0-root.io.3
Original advisory text
CVE-2026-46595 in golang.org/x/crypto - Patched by Root
Root has patched CVE-2026-46595 in the golang.org/x/crypto package for Root:Go. Multiple fixed versions available.
References
Severity
10.0 Critical
Exploitation
EPSS <1%
Type
CWE-863Incorrect Authorization
CWE-303Incorrect Implementation of Authentication Algorithm
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen22 May 2026
Monitor software like this
Free during beta