SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f6x5-jh6r-wrfv | golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 20 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CVE-2025-47914 in golang.org/x/crypto/ssh/agent | Malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agent |
Wed, 19 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 | |
| Metrics |
cvssV3_1
|
Wed, 19 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read. | |
| Title | CVE-2025-47914 in golang.org/x/crypto/ssh/agent | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-11-20T17:15:00.344Z
Reserved: 2025-05-13T23:31:29.597Z
Link: CVE-2025-47914
Updated: 2025-11-19T20:50:22.359Z
Status : Received
Published: 2025-11-19T21:15:50.517
Modified: 2025-11-19T21:15:50.517
Link: CVE-2025-47914
No data.
OpenCVE Enrichment
No data.
Github GHSA