SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang crypto Golang ssh |
|
| Vendors & Products |
Golang
Golang crypto Golang ssh |
Thu, 20 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CVE-2025-47914 in golang.org/x/crypto/ssh/agent | Malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agent |
Wed, 19 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 | |
| Metrics |
cvssV3_1
|
Wed, 19 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read. | |
| Title | CVE-2025-47914 in golang.org/x/crypto/ssh/agent | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published: 2025-11-19T20:33:43.126Z
Updated: 2025-11-20T17:15:00.344Z
Reserved: 2025-05-13T23:31:29.597Z
Link: CVE-2025-47914
Updated: 2025-11-19T20:50:22.359Z
Status : Awaiting Analysis
Published: 2025-11-19T21:15:50.517
Modified: 2025-11-21T15:13:59.083
Link: CVE-2025-47914
No data.