Launch Week Day 1: Announcing Security Design Review
UNKNOWN Go

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

GO-2026-5033 · CVE-2026-46598

Published · Modified

Description

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.

Ready to move

Start Securing

Free, no credit card | First findings in minutes