Junglewise Threat Intelligence

CVE-2026-39830: Go x/crypto/ssh resource leak via unsolicited global request responses

CVE-2026-39830 · Severity: critical · CVSS 9.1 · Published 2026-05-22

Technologies: golang.org/x/crypto/ssh (Go), golang.org/x/crypto (Go). Vendors: Go, Go Project.

Executive brief

A vulnerability in the Go SSH library could allow a malicious user to cause a server to stop responding or leak system resources. By sending unexpected messages, an attacker can block the server's ability to process connections, potentially leading to a complete service outage. This affects any Go-based application or service that uses this library to handle SSH connections.

Technical details

A vulnerability in the golang.org/x/crypto/ssh package allows a malicious SSH peer to trigger a deadlock in the connection's read loop. By sending unsolicited global request responses, an attacker can fill an internal buffer, blocking the associated goroutine. This blocked state cannot be recovered by calling Close(), leading to a persistent resource leak and potential denial of service for the server. The issue is rooted in improper handling of unexpected global responses, which are now discarded in patched versions. The vulnerability is reachable over the network without authentication.

Affected products

  • Go Project golang.org/x/crypto/ssh < 0.52.0

Timeline

  • 2026-05-21: other: Issue reported by NCC Group Cryptography Services
  • 2026-05-22: disclosed: NVD publication date
  • 2026-06-25: advisory: GitHub Advisory published

References

Related threats