VYPR
Critical severity9.1NVD Advisory· Published May 22, 2026· Updated Sep 16, 2026

CVE-2026-39830

CVE-2026-39830

Description

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
golang.org/x/cryptoGo
< 0.52.00.52.0

Affected products

2815

Patches

Vulnerability mechanics

References

63

News mentions

0

No linked articles in our index yet.