Came across something in go.mod around line 1 that looked worth flagging.
CRITICAL vulnerability (CVE-2026-56854) in golang.org/x/crypto v0.51.0, affecting the SSH server implementation. The 'source-address' critical option set in Permissions by authentication callbacks (PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin) was silently ignored — it was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths (extending the incomplete fix for CVE-2026-46595). Impact: a client authenticating via password, keyboard-interactive, no-auth, or GSSAPI can connect from arbitrary, unauthorized IP addresses, bypassing source-IP restrictions the application intended to enforce. This is a remote authorization/access-control bypass (CWE-284) that can expose SSH servers reachable only from trusted hosts. Risk level: CRITICAL — remote bypass of a security control with no user interaction required; valid credentials are the only prerequisite. Remediation: upgrade to golang.org/x/crypto v0.55.0, where the source-address check is applied to Permissions returned by ALL authentication callbacks. As defense in depth, also consider enforcing IP allowlists at the network/ingress layer rather than relying solely on the SSH critical option.
Something like this might fix it:
--- a/go.mod
+++ b/go.mod
@@
require (
- golang.org/x/crypto v0.51.0
+ golang.org/x/crypto v0.55.0
)
Then run:
go get golang.org/x/crypto@v0.55.0
go mod tidy
go build ./... && go test ./...
This bumps the dependency to the patched release (v0.55.0) and updates go.sum. No application code changes are required — the fix enforces source-address restrictions for all SSH authentication callback paths server-side.
For reference: rule CVE-2026-56854. Rated critical.
I have not run the test suite here, so treat the suggestion as a starting point rather than something ready to merge.
Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.
Came across something in
go.modaround line 1 that looked worth flagging.CRITICAL vulnerability (CVE-2026-56854) in golang.org/x/crypto v0.51.0, affecting the SSH server implementation. The 'source-address' critical option set in Permissions by authentication callbacks (PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin) was silently ignored — it was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths (extending the incomplete fix for CVE-2026-46595). Impact: a client authenticating via password, keyboard-interactive, no-auth, or GSSAPI can connect from arbitrary, unauthorized IP addresses, bypassing source-IP restrictions the application intended to enforce. This is a remote authorization/access-control bypass (CWE-284) that can expose SSH servers reachable only from trusted hosts. Risk level: CRITICAL — remote bypass of a security control with no user interaction required; valid credentials are the only prerequisite. Remediation: upgrade to golang.org/x/crypto v0.55.0, where the source-address check is applied to Permissions returned by ALL authentication callbacks. As defense in depth, also consider enforcing IP allowlists at the network/ingress layer rather than relying solely on the SSH critical option.
Something like this might fix it:
For reference: rule
CVE-2026-56854. Rated critical.I have not run the test suite here, so treat the suggestion as a starting point rather than something ready to merge.
Found with automated scanning (RedGem) and reviewed before opening. If it is not useful, closing it is completely fine.