Junglewise Threat Intelligence

CVE-2026-39833: Go x/crypto/ssh/agent missing enforcement of ConfirmBeforeUse constraint

CVE-2026-39833 · Severity: critical · CVSS 9.1 · Published 2026-05-22

Technologies: golang.org/x/crypto/ssh/agent (Go), golang.org/x/crypto (Go). Vendors: Go.

Executive brief

A vulnerability was found in the Go SSH agent library, which is used to manage cryptographic keys for secure remote access. The library failed to enforce a security setting that requires user confirmation before a key is used for signing. This could allow an attacker to use a stored key to sign data or authenticate to other systems without the owner's knowledge or approval.

Technical details

The in-memory keyring implementation in golang.org/x/crypto/ssh/agent, specifically the NewKeyring() function, silently accepts keys with the 'ConfirmBeforeUse' constraint but fails to enforce it. When a signing request is made, the agent performs the operation without prompting the user for confirmation, providing no indication that the security constraint was ignored. This is classified as a missing authorization check (CWE-862). An attacker with access to the agent could perform signing operations that should have required manual approval. The issue is fixed in version 0.52.0, where NewKeyring() now returns an error if unsupported constraints are requested.

Affected products

  • Go golang.org/x/crypto/ssh/agent < 0.52.0

Timeline

  • 2026-05-16: disclosed: Issue reported to Go project
  • 2026-05-22: advisory: NVD and Go vulnerability report published
  • 2026-06-25: advisory: GitHub Advisory published

References

Related threats