CVE-2025-22869: Go SSH

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

Affected products

  • Go SSH: before 0.35.0 (fixed in 0.35.0)

Published 2025-02-26. Last modified 2026-06-17.