Executive brief
A security issue was identified in a Go library used for managing SSH known hosts files. The library failed to properly check if a Certificate Authority (CA) signature key had been revoked, potentially allowing unauthorized users to bypass authentication. This could lead to unauthorized access to systems or data that rely on this library for SSH connection security.
Technical details
A vulnerability in the golang.org/x/crypto/ssh/knownhosts package (specifically within the hostKeyDB.IsRevoked function) allows for authentication bypass. The library previously failed to check the revocation status of a 'SignatureKey' belonging to a Certificate Authority (CA) when processing known_hosts files. An attacker could potentially use a revoked key to successfully authenticate if the library does not recognize the @revoked marker for the CA's signature key. The issue is fixed in version 0.52.0 by ensuring both the key and the key.SignatureKey are validated against the revoked list.
Affected products
- Go Project golang.org/x/crypto/ssh/knownhosts < 0.52.0
Timeline
- 2026-05-22: disclosed: NVD published date
- 2026-06-25: advisory: GitHub Advisory published