VDB
GCVE-110-MAGEIA-2026-179
GCVE-110-MAGEIA-2026-179
Advisory Published
fixes a protocol weakness in the golang.org/x/crypto/ssh package that
allowed a MITM attacker to compromise the integrity of the secure
channel before it was established, allowing them to prevent transmission
of a number of messages immediately after the secure channel was
established without either side being aware.
The impact of this attack is relatively limited, as it does not
compromise confidentiality of the channel. Notably this attack would
allow an attacker to prevent the transmission of the SSH2_MSG_EXT_INFO
message, disabling a handful of newer security features.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | golang-x-sys | 0 (affected), 0.30.0-2.mga9 (unaffected) | — |
| Mageia | golang-x-crypto | 0 (affected), 0.45.0-1.mga9 (unaffected) | — |
References
Browse GCVE Records
74,132 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.