When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:35833 cve-icon
https://access.redhat.com/errata/RHSA-2026:36199 cve-icon
https://access.redhat.com/errata/RHSA-2026:36319 cve-icon
https://access.redhat.com/errata/RHSA-2026:36625 cve-icon
https://access.redhat.com/errata/RHSA-2026:36648 cve-icon
https://access.redhat.com/errata/RHSA-2026:36651 cve-icon
https://access.redhat.com/errata/RHSA-2026:36796 cve-icon
https://access.redhat.com/errata/RHSA-2026:36797 cve-icon
https://access.redhat.com/errata/RHSA-2026:37072 cve-icon
https://access.redhat.com/errata/RHSA-2026:37123 cve-icon
https://access.redhat.com/errata/RHSA-2026:37271 cve-icon
https://access.redhat.com/errata/RHSA-2026:37387 cve-icon
https://access.redhat.com/errata/RHSA-2026:37410 cve-icon
https://access.redhat.com/errata/RHSA-2026:40118 cve-icon
https://access.redhat.com/errata/RHSA-2026:40262 cve-icon
https://access.redhat.com/errata/RHSA-2026:40945 cve-icon
https://access.redhat.com/errata/RHSA-2026:40972 cve-icon
https://access.redhat.com/errata/RHSA-2026:41019 cve-icon
https://access.redhat.com/errata/RHSA-2026:41031 cve-icon
https://access.redhat.com/errata/RHSA-2026:41036 cve-icon
https://access.redhat.com/errata/RHSA-2026:41066 cve-icon
https://access.redhat.com/errata/RHSA-2026:42146 cve-icon
https://access.redhat.com/errata/RHSA-2026:42796 cve-icon
https://access.redhat.com/errata/RHSA-2026:43052 cve-icon
https://access.redhat.com/errata/RHSA-2026:43692 cve-icon
https://access.redhat.com/errata/RHSA-2026:49944 cve-icon
https://access.redhat.com/errata/RHSA-2026:52857 cve-icon
https://access.redhat.com/errata/RHSA-2026:52910 cve-icon
https://access.redhat.com/security/cve/CVE-2026-39832 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2480685 cve-icon
https://go.dev/cl/778640 cve-icon cve-icon
https://go.dev/cl/778641 cve-icon cve-icon
https://go.dev/issue/79435 cve-icon cve-icon
https://groups.google.com/g/golang-announce/c/a082jnz-LvI cve-icon cve-icon
https://pkg.go.dev/vuln/GO-2026-5006 cve-icon cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json cve-icon
History

Tue, 11 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
References

Tue, 11 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
References

Tue, 11 Aug 2026 16:00:00 +0000


Thu, 28 May 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290

Thu, 28 May 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Golang crypto
Weaknesses CWE-502
CPEs cpe:2.3:a:golang:crypto:*:*:*:*:*:go:*:*
Vendors & Products Golang crypto

Fri, 22 May 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 22 May 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Golang
Golang ssh
Vendors & Products Golang
Golang ssh

Fri, 22 May 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290

Fri, 22 May 2026 03:30:00 +0000

Type Values Removed Values Added
Description When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
Title Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-08-12T12:04:49.246Z

Reserved: 2026-04-07T18:13:03.529Z

Link: CVE-2026-39832

cve-icon Vulnrichment

Updated: 2026-08-12T12:04:49.246Z

cve-icon NVD

Status : Modified

Published: 2026-05-22T04:16:22.663

Modified: 2026-08-12T12:19:05.140

Link: CVE-2026-39832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T19:45:25Z

Weaknesses