CVE-2026-39834
cAdvisor vulnerability analysis and mitigation

Overview

CVE-2026-39834 is an integer overflow vulnerability in the golang.org/x/crypto/ssh package that causes an infinite loop when writing data larger than 4GB in a single SSH channel Write call. The flaw affects all versions of golang.org/x/crypto prior to 0.52.0. It was published on May 22, 2026, and has a CVSS v3.1 base score of 9.1 (Critical) with no authentication required for exploitation (pkg.go.dev, Feedly).

Technical details

The root cause is an integer overflow (CWE-190) in the internal payload size calculation within the SSH channel write loop of golang.org/x/crypto/ssh. When a caller passes a buffer exceeding 4GB (the 32-bit integer boundary), the size variable truncates, causing the loop condition to never advance — resulting in an infinite loop that continuously sends empty SSH packets. The fix, applied in Go change list 781663, replaces the size comparison variable type with int64 to prevent truncation. The vulnerability is reachable over the network without authentication, as an attacker only needs to establish an SSH connection and trigger a large write operation (pkg.go.dev, oss-sec).

Impact

Successful exploitation causes the affected SSH channel's write loop to spin indefinitely, consuming CPU and potentially exhausting server resources, resulting in a denial of service for legitimate users. Because no authentication is required, any network-accessible service built on golang.org/x/crypto/ssh — including tools like rclone, Portainer, and Pulumi Kubernetes — is potentially affected. Integrity is also rated HIGH in the CVSS score, reflecting the possibility that the infinite loop disrupts data transmission guarantees on the SSH channel (Feedly, pkg.go.dev).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of this report (Feedly). The EPSS score is approximately 0.018%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Despite the lack of active exploitation, the unauthenticated network attack vector and wide adoption of golang.org/x/crypto across the Go ecosystem make it a meaningful risk for unpatched deployments.

Exploitation steps

  1. Reconnaissance: Identify services built on golang.org/x/crypto/ssh versions prior to 0.52.0 that are exposed to the network (e.g., using Shodan, Censys, or banner grabbing to identify Go-based SSH services).
  2. Establish SSH connection: Initiate a standard SSH connection to the target service. No credentials are required if the service accepts unauthenticated connections or if credentials are otherwise available.
  3. Open an SSH channel: After connection, open an SSH channel (e.g., a session or direct-tcpip channel) as part of the normal SSH protocol handshake.
  4. Trigger large Write call: Send a single Write call on the SSH channel with a payload exceeding 4GB (2^32 bytes). This causes the internal int32 size variable to overflow and truncate to zero or a small value.
  5. Induce infinite loop: The truncated size causes the write loop's progress condition to never be satisfied, locking the goroutine in an infinite loop sending empty packets and consuming server CPU/resources, resulting in denial of service (pkg.go.dev, oss-sec).

Indicators of compromise

  • Network: Sustained high-volume SSH connections from a single source IP with abnormally large data transfer attempts; SSH sessions that remain open indefinitely without completing data transfer.
  • Process: Go-based SSH server processes showing 100% CPU utilization on one or more goroutines; process hangs or unresponsiveness correlated with active SSH sessions.
  • Logs: SSH server logs showing sessions that open channels but never close them; application logs indicating stalled or non-progressing write operations on SSH channels.
  • System: Elevated system load average without corresponding legitimate workload; SSH service becoming unresponsive to new connection attempts due to resource exhaustion.

Mitigation and workarounds

The primary remediation is to upgrade golang.org/x/crypto to version 0.52.0 or later, which fixes the integer overflow by using int64 for the size comparison (pkg.go.dev). Downstream projects such as rclone, Portainer (fixed in 2.39.3), and Pulumi Kubernetes have already released updates incorporating the patched library (Portainer Release). As a temporary workaround, implement network-level rate limiting or connection limits on SSH services, and consider adding application-level timeouts for SSH write operations to prevent indefinite blocking. Amazon Linux 2, Amazon Linux 2023, and openSUSE have also issued security advisories with updated packages (Amazon Linux, openSUSE).

Community reactions

The Go security team disclosed the vulnerability via the golang-announce mailing list and published a detailed advisory in the Go vulnerability database (golang-announce). The oss-sec mailing list also carried the disclosure, prompting awareness in the open-source security community (oss-sec). Multiple Linux distributions including openSUSE and Amazon Linux issued security advisories, and several downstream Go projects rapidly released patched versions, reflecting the broad reach of the golang.org/x/crypto library in the ecosystem.

Additional resources


SourceThis report was generated using AI

Related cAdvisor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-39822HIGH7.8
  • Go logoGo
  • k3s
NoYesJul 08, 2026
CVE-2026-56852HIGH7.5
  • cAdvisor logocAdvisor
  • crossplane-provider-azure-servicefabric
NoYesJul 21, 2026
CVE-2026-46600HIGH7.5
  • cAdvisor logocAdvisor
  • rook-ceph-fips-1.19
NoYesJul 21, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • crossplane-provider-aws-autoscalingplans-fips
NoYesJul 08, 2026
CVE-2026-41579LOW3.3
  • cAdvisor logocAdvisor
  • nvidia-device-plugin-fips
NoYesJul 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management