Skip to content

Possible fix(deps): golang.org/x/crypto v0.51.0 → 0.55.0 (CVE-2026-56854) in go.mod #10

Description

@begininvoke

Came across something in go.mod around line 1 that looked worth flagging.

CRITICAL vulnerability (CVE-2026-56854) in golang.org/x/crypto v0.51.0, affecting the SSH server implementation. The 'source-address' critical option set in Permissions by authentication callbacks (PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin) was silently ignored — it was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths (extending the incomplete fix for CVE-2026-46595). Impact: a client authenticating via password, keyboard-interactive, no-auth, or GSSAPI can connect from arbitrary, unauthorized IP addresses, bypassing source-IP restrictions the application intended to enforce. This is a remote authorization/access-control bypass (CWE-284) that can expose SSH servers reachable only from trusted hosts. Risk level: CRITICAL — remote bypass of a security control with no user interaction required; valid credentials are the only prerequisite. Remediation: upgrade to golang.org/x/crypto v0.55.0, where the source-address check is applied to Permissions returned by ALL authentication callbacks. As defense in depth, also consider enforcing IP allowlists at the network/ingress layer rather than relying solely on the SSH critical option.

Something like this might fix it:

--- a/go.mod
+++ b/go.mod
@@
 require (
-	golang.org/x/crypto v0.51.0
+	golang.org/x/crypto v0.55.0
 )

Then run:
  go get golang.org/x/crypto@v0.55.0
  go mod tidy
  go build ./... && go test ./...

This bumps the dependency to the patched release (v0.55.0) and updates go.sum. No application code changes are required — the fix enforces source-address restrictions for all SSH authentication callback paths server-side.

For reference: rule CVE-2026-56854. Rated critical.

I have not run the test suite here, so treat the suggestion as a starting point rather than something ready to merge.


Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions