NONE · 0

CVE-2026-39835

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an ...

Vulnerability Description

SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.

References

FAQ

What is CVE-2026-39835?

CVE-2026-39835 is a documented vulnerability. SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an ...

How severe is CVE-2026-39835?

CVSS scoring is not yet available for CVE-2026-39835. Check NVD for updates.

Is there a patch for CVE-2026-39835?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.