Review reviewHigh
CVE-2026-46597
golang.org/x/crypto golang.org/x/crypto/ssh, crypto
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
- CVSS
- 7.5
- EPSS
- 0.47% 38.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.22