CVE-2026-39830
cAdvisor Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-39830 is a denial-of-service vulnerability in Go's golang.org/x/crypto/ssh package where a malicious SSH peer can send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop indefinitely. The blocked goroutine cannot be released even by calling Close(), resulting in a resource leak per connection. All versions of golang.org/x/crypto before 0.52.0 are affected. The vulnerability was published on May 22, 2026, and carries a CVSS v3.1 base score of 9.1 (Critical) (pkg.go.dev, EUVD).

Dettagli tecnici

The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The Go SSH library's connection read loop processes incoming SSH messages, including global request responses, without discarding unsolicited ones. A malicious SSH peer — acting as either a client or server — can flood the internal response channel buffer with unsolicited global request responses, causing the goroutine handling the read loop to block permanently. Because the goroutine cannot be unblocked via Close(), each such connection results in a persistent goroutine and resource leak. The fix, introduced in version 0.52.0, discards unsolicited global responses rather than queuing them (pkg.go.dev, Go Issue, Go CL 781640).

Impatto

Successful exploitation allows an unauthenticated network attacker to cause a denial of service by hanging SSH connections and leaking goroutine resources on the affected server or client. Over multiple connections, this can exhaust system memory and goroutine limits, effectively crashing or rendering unresponsive any Go application using the golang.org/x/crypto/ssh package for SSH communication. Confidentiality impact is rated High by NVD (CVSS), though the primary real-world consequence is availability loss; there is no evidence of direct data exfiltration via this vector (pkg.go.dev, EUVD).

Passaggi di sfruttamento

  1. Reconnaissance: Identify services built with Go that use golang.org/x/crypto/ssh versions prior to 0.52.0 — this includes SSH servers, clients, or any application embedding Go SSH functionality (e.g., Portainer, rclone, Pulumi Kubernetes provider).
  2. Establish SSH connection: Initiate a standard SSH connection to the target service. No credentials are required to begin the protocol handshake.
  3. Send unsolicited global request responses: During or after the SSH handshake, send a high volume of SSH SSH_MSG_REQUEST_SUCCESS or SSH_MSG_REQUEST_FAILURE messages (global request responses) that were never requested by the server.
  4. Fill internal buffer: The target's read loop goroutine attempts to queue these responses into an internal channel buffer. Once the buffer is full, the goroutine blocks indefinitely.
  5. Trigger resource leak: Repeat across multiple connections. Each blocked goroutine cannot be freed by Close(), causing cumulative goroutine and memory leaks that degrade or crash the target service (Go Issue, pkg.go.dev).

Indicatori di compromesso

  • Network: Unusual volume of SSH connections from a single source IP that do not complete normal authentication flows; connections that remain open indefinitely without activity.
  • Process/Runtime: Rapidly increasing goroutine count in Go application metrics (e.g., runtime.NumGoroutine() growing unboundedly); elevated memory consumption in SSH-serving Go processes.
  • Logs: SSH connection log entries showing connections established but never cleanly terminated; absence of normal disconnect or timeout log entries for established sessions.
  • System: Increasing file descriptor usage associated with the Go SSH process; system-level OOM (out-of-memory) events or process crashes in applications using golang.org/x/crypto/ssh (Go Issue, oss-sec).

Mitigazione e soluzioni alternative

The primary remediation is to update golang.org/x/crypto to version 0.52.0 or later, which discards unsolicited global SSH responses instead of queuing them. Applications and distributions that bundle this package — including rclone, Portainer, Pulumi Kubernetes provider, and others — should update to their respective patched releases. As a network-level workaround, restrict SSH access to trusted peers only using firewall rules or network segmentation to reduce exposure until patching is complete (pkg.go.dev, Go CL 781640, Go CL 781664).

Reazioni della comunità

The Go security team disclosed the vulnerability via the golang-announce mailing list and published a Go vulnerability database entry (GO-2026-5017). The issue was also discussed on the oss-security mailing list. Multiple Linux distributions including openSUSE and Amazon Linux 2/2023 issued security advisories and package updates. Downstream projects such as rclone, Portainer, and Pulumi Kubernetes provider have released patched versions incorporating the fix (golang-announce, oss-sec, rclone changelog, Portainer release).

Risorse aggiuntive


FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato cAdvisor Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-39822HIGH7.8
  • Go logoGo
  • victoriatraces-fips
NoJul 08, 2026
CVE-2026-56852HIGH7.5
  • cAdvisor logocAdvisor
  • aws-otel-collector-fips
NoJul 21, 2026
CVE-2026-46600HIGH7.5
  • cAdvisor logocAdvisor
  • paketo-buildpacks-rails-assets
NoJul 21, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • kubescape-downloader-fips
NoJul 08, 2026
CVE-2026-41579LOW3.3
  • cAdvisor logocAdvisor
  • cadvisor
NoJul 01, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità