An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HGolang Crypto
APPGolang< 0.52.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-39833CRITICAL9.1PL ✓same product
Golang Crypto: brak wymuszenia ograniczenia ConfirmBeforeUse w NewKeyring()
CVE-2026-39830CRITICAL9.1PL ✓same product
Golang Crypto: resource leak przez niezamawiane odpowiedzi SSH global request
CVE-2026-39831CRITICAL9.1PL ✓same product
Brak weryfikacji flagi User Presence w FIDO/U2F w Golang Crypto
CVE-2026-39832CRITICAL9.1PL ✓same product
Golang Crypto: pominięcie ograniczeń przy przekazywaniu kluczy do zdalnego agenta SSH
CVE-2026-39834CRITICAL9.1PL ✓same product
Integer overflow w Golang Crypto SSH — nieskończona pętla przy zapisie >4GB