CVE-2026-46595: Golang Crypto

Critical severity, CVSS 10.0. EPSS: 0.5% chance of exploitation in the next 30 days.

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

Affected products

  • Golang Crypto: before 0.52.0 (fixed in 0.52.0)

Published 2026-05-22. Last modified 2026-09-11.