THREAT OPS › Threat News › [NVD] CVE-2026-39835 (MEDIUM 5.3) — SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
[NVD] CVE-2026-39835 (MEDIUM 5.3) — SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835 CVSS: 5.3 MEDIUM Published: 2026-05-22T04:16:24.530
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
Indicators of compromise
- CVE-2026-39835cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-39835