A cryptographic implementation review of Go's golang.org/x/crypto/ssh package found 15 issues and led to coordinated fixes for nine CVEs affecting SSH client and server functionality. NCC Group said the assessment, commissioned by Teleport in early 2026, concluded that the codebase was generally well structured and documented but uncovered security flaws including certificate restriction bypasses, denial-of-service conditions, deadlocks, infinite loops, panics, and failures in SSH agent constraint enforcement.
The vulnerabilities were remediated with the release of golang.org/x/crypto version v0.52.0, which was published on May 22, 2026, alongside an announcement to the Golang Announce group. The review also noted that any future post-quantum cryptography support in x/crypto/ssh should be implemented carefully within the package's existing framework to avoid introducing new weaknesses.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The x/crypto v0.52.0 release containing the SSH fixes was announced on the Golang Announce group after the coordinated remediation effort.
The identified issues were remediated in golang.org/x/crypto version 0.52.0, which addressed the vulnerabilities found in the x/crypto/ssh review.
During the review, NCC Group documented 15 findings in x/crypto/ssh and related components, leading to nine filed CVEs covering certificate restriction bypasses, denial-of-service conditions, deadlocks, infinite loops, panics, and SSH agent constraint enforcement failures.
In early 2026, Teleport engaged NCC Group's Cryptography Services practice to review the Go x/crypto/ssh package, with Geomys providing technical support and coordinating remediation and disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.