)]}'
{
  "commit": "533fb3f7e4a5ae23f69d1837cd851d35ff5b76ce",
  "tree": "2215c94ae92c2aea2cc51e5e7bca2e4972fb14f8",
  "parents": [
    "abbc44d451a6f9236a2bbd26cbcd4d0fec473da3"
  ],
  "author": {
    "name": "Neal Patel",
    "email": "nealpatel@google.com",
    "time": "Fri May 15 19:57:52 2026 +0000"
  },
  "committer": {
    "name": "Neal Patel",
    "email": "nealpatel@google.com",
    "time": "Thu May 21 17:03:26 2026 -0700"
  },
  "message": "ssh: fix source-address critical option bypass\n\nPreviously, CVE-2024-45337 fixed an authorization bypass\nfor misused ssh server configurations; if any other type\nof callback is passed other than public key, then the\nsource-address validation would be skipped.\n\nFixes CVE-2026-46595\nFixes golang/go#79570\n\nChange-Id: I08d86a961048a232c8672f23000e693ed5a0e2fd\nReviewed-on: https://go-review.googlesource.com/c/crypto/+/781642\nLUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com \u003cgolang-scoped@luci-project-accounts.iam.gserviceaccount.com\u003e\nReviewed-by: Neal Patel \u003cnealpatel@google.com\u003e\nReviewed-by: Roland Shoemaker \u003croland@golang.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "dd1c32716d0c4ff641c3736f6f278b36c305e6d0",
      "old_mode": 33188,
      "old_path": "ssh/server.go",
      "new_id": "0192a6750378d58badb1795b458c77f57c57dd42",
      "new_mode": 33188,
      "new_path": "ssh/server.go"
    },
    {
      "type": "modify",
      "old_id": "2982ca3f496617e87e01af1a018912c3455a6709",
      "old_mode": 33188,
      "old_path": "ssh/server_test.go",
      "new_id": "2900b61a4d07494fe4de6a2ad729f2fd47f42593",
      "new_mode": 33188,
      "new_path": "ssh/server_test.go"
    }
  ]
}
