{"id":"CVE-2026-56855","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-56855","summary":"Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh","details":"Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.\n\nNow, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.","published":"2026-09-02T19:12:04Z","modified":"2026-09-03T10:10:55.101133330Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"golang.org/x/crypto","fixedVersion":"0.56.0"}],"fix":null,"references":[{"type":"REPORT","url":"https://go.dev/issue/81317"},{"type":"FIX","url":"https://go.dev/cl/826524"},{"type":"WEB","url":"https://groups.google.com/g/golang-announce/c/1y3fb2np35U"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T10:10:55.101133330Z"}}