Vulnerability Report: GO-2025-4116
- CVE-2025-47913
- Affects: golang.org/x/crypto
- Published: Nov 13, 2025
- Modified: Dec 16, 2025
SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.43.0
6 unexported affected symbols
- agentKeyringSigner.Sign
- agentKeyringSigner.SignWithAlgorithm
- client.List
- client.Sign
- client.SignWithFlags
- client.Signers
Aliases
References
- https://go.dev/cl/700295
- https://go.dev/issue/75178
- https://github.com/advisories/GHSA-56w8-48fp-6mgv
- https://vuln.go.dev/ID/GO-2025-4116.json
Credits
- Jakub Ciolek, Nicola Murino
Feedback
See anything missing or incorrect?
Suggest an edit to this report.