{"id":"CVE-2020-29652","aliases":["GHSA-3vm4-22fp-5rfm","GO-2021-0227"],"url":"https://o3.security/vulnerability/CVE-2020-29652","summary":"golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability","details":"A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers. An attacker can craft an authentication request message for the `gssapi-with-mic` method which will cause NewServerConn to panic via a nil pointer dereference if ServerConfig.GSSAPIWithMICConfig is nil.","published":"2020-12-17T05:15:10.580Z","modified":"2026-03-14T14:48:57.452874Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"golang.org/x/crypto","fixedVersion":"0.0.0-20201216223049-8b5274cf687f"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff%40%3Cnotifications.skywalking.apache.org%3E"},{"type":"ADVISORY","url":"https://go-review.googlesource.com/c/crypto/+/278852"},{"type":"ADVISORY","url":"https://groups.google.com/g/golang-announce/c/ouZIlBimOsE?pli=1"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-29652"},{"type":"WEB","url":"https://go.dev/cl/278852"},{"type":"WEB","url":"https://go.googlesource.com/crypto/+/8b5274cf687fd9316b4108863654cc57385531e8"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff@%3Cnotifications.skywalking.apache.org%3E"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2021-0227"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-14T14:48:57.452874Z"}}