CVE-2026-39827
Last modified
CVE-2026-39827 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Golang | Crypto | < 0.52.0 |
References
- https://go.dev/cl/781320Issue Tracking
- https://go.dev/issue/35127Issue Tracking
- https://pkg.go.dev/vuln/GO-2026-5016Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-39827?
How severe is CVE-2026-39827?
How do I fix CVE-2026-39827?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-39821The ToASCII and ToUnicode functions incorrectly accept Punyc…9.6
- CVE-2026-39822On Unix systems, opening a file in an os.Root improperly fol…7.8
- CVE-2026-39823CVE-2026-27142 fixed a vulnerability in which URLs were not …6.1
- CVE-2026-39824NewNTUnicodeString does not check for string length overflow…3.3
- CVE-2026-39825ReverseProxy can forward queries containing parameters not v…5.3
- CVE-2026-39826If a trusted template author were to write a <script> tag co…6.1
- CVE-2026-39828When an SSH server authentication callback returned PartialS…6.3
- CVE-2026-39829The RSA and DSA public key parsers did not enforce size limi…7.5
- CVE-2026-3983A security flaw has been discovered in Campcodes Division Re…3.5
- CVE-2026-39830A malicious SSH peer could send unsolicited global request r…9.1
- CVE-2026-39831The Verify() method for FIDO/U2F security key types (sk-ecds…9.1
- CVE-2026-39832When adding a key to a remote agent constraint extensions su…9.1
Are you affected by CVE-2026-39827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
