ZeroHour

CVE-2026-39827

CVSS 3.1
6.5 medium
EPSS
<1%p20
Published
()
Modified
Description

An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.

Vendors
golang
Products
crypto
Weakness
CWE-924
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.