Skip to content

Assess 12 new x/crypto/ssh CVEs; extend all .snyk expiries to 2026-06-21#237

Merged
JonJagger merged 3 commits into
mainfrom
assess-new-ssh-cves
May 23, 2026
Merged

Assess 12 new x/crypto/ssh CVEs; extend all .snyk expiries to 2026-06-21#237
JonJagger merged 3 commits into
mainfrom
assess-new-ssh-cves

Conversation

@JonJagger
Copy link
Copy Markdown
Member

All new vulnerabilities are in golang.org/x/crypto/ssh and /ssh/agent, fixed upstream in v0.52.0. None are exploitable by user code: --net=none prevents any SSH connection from sandbox containers, and the runner does not expose an SSH server or agent. Expiry dates rolled forward 29 days.

JonJagger and others added 3 commits May 23, 2026 06:50
All new vulnerabilities are in golang.org/x/crypto/ssh and /ssh/agent,
fixed upstream in v0.52.0. None are exploitable by user code: --net=none
prevents any SSH connection from sandbox containers, and the runner does
not expose an SSH server or agent. Expiry dates rolled forward 29 days.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
20 CVE/Snyk assessment files removed -- these vulnerabilities no longer
appear in the current snyk container test output, meaning they have been
patched in the base image. readme.txt updated to match.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@JonJagger JonJagger merged commit 576bf1d into main May 23, 2026
34 checks passed
@JonJagger JonJagger deleted the assess-new-ssh-cves branch May 23, 2026 06:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant