VULNRABLE / Vulnerability / CVE-2026-56854

CVE-2026-56854

UNKNOWN LOW golang.org/x/crypto OSV

Exploit verdict: No active-exploit signal

CVSS Score
Severity
UNKNOWN
EPSS
0%
Source
OSV

Summary

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

What this means

CVE-2026-56854 is a unknown-severity vulnerability affecting golang.org/x/crypto. The EPSS model estimates a 0% probability of exploitation in the next 30 days. Published August 28, 2026.

View full advisory at OSV →