CVE-2024-39223: Ginuerzh Gost

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey

Affected products

  • Ginuerzh Gost: up to and including 2.11.5

Published 2024-07-03. Last modified 2026-06-17.