CVE-2025-22869: Go SSH
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.
Affected products
- Go SSH: before 0.35.0 (fixed in 0.35.0)
Published 2025-02-26. Last modified 2026-06-17.