Junglewise Threat Intelligence

CVE-2026-39827: Go x/crypto/ssh memory leak in channel rejection

CVE-2026-39827 · Severity: medium · CVSS 6.5 · Published 2026-05-22

Technologies: golang.org/x/crypto/ssh (Go), golang.org/x/crypto (Go). Vendors: Go.

Executive brief

A vulnerability in the Go SSH library can allow a connected user to crash a server by repeatedly requesting new communication channels. When the server rejects these requests, it fails to properly clear them from memory, leading to a memory leak. This eventually exhausts system resources, causing the service to crash and become unavailable to all users.

Technical details

A memory leak exists in golang.org/x/crypto/ssh due to improper handling of rejected channel requests. When a server rejects a channel open request using the 'channel.Reject' function, the internal state of the connection fails to remove the rejected channel object, preventing it from being garbage collected. An authenticated attacker can exploit this by repeatedly opening and forcing the rejection of channels, leading to unbounded memory growth and an eventual OOM (Out of Memory) crash. This affects any SSH server implementation using the vulnerable library versions. The issue is resolved in version 0.52.0 by ensuring rejected channels are properly removed from the connection's internal state.

Affected products

  • Go crypto/ssh < 0.52.0

Timeline

  • 2019-10-24: other: Issue originally opened on GitHub
  • 2026-05-22: advisory: NVD published date
  • 2026-06-25: disclosed: GitHub Advisory published
  • 2026-06-25: patched: Version 0.52.0 released

References

Related threats