An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 22 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-680 CWE-704 |
Fri, 22 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs. | |
| Title | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-05-22T02:31:26.754Z
Reserved: 2026-05-15T17:35:00.813Z
Link: CVE-2026-46597
No data.
Status : Received
Published: 2026-05-22T04:16:26.003
Modified: 2026-05-22T04:16:26.003
Link: CVE-2026-46597
No data.
OpenCVE Enrichment
Updated: 2026-05-22T04:30:25Z