Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2026-39829

CVE-2026-39829

None
Open
TLP:CLEAR

Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh

NVD CVE.org
Critical Infrastructure

AI Analysis

No AI analysis yet.

Description

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

Details

EPSS Score
0.47%

38.1th percentile

Confidence
90%
Published
May 22, 2026
Last Modified
Aug 11, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.