CVE-2026-39832

Published May 22, 2026

Last updated 18 hours ago

Overview

Description
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
Source
security@golang.org
NVD status
Modified
Products
crypto

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

nvd@nist.gov
CWE-502
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-281

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.