ssh: enforce the source-address critical option for all auth callbacks CVE-2026-46595 extended source-address validation, historically applied only to the Permissions returned by PublicKeyCallback, to the ones returned by VerifiedPublicKeyCallback. The documented contract of Permissions.CriticalOptions does not restrict enforcement to a specific authentication method, so move the check to a single point at the end of each authentication attempt, where it covers the Permissions returned by any callback (password, keyboard-interactive, none and GSSAPI included). The check at public key cache insertion time is kept: it remains authoritative for the Permissions returned by PublicKeyCallback, which VerifiedPublicKeyCallback may replace before the check at the end of the authentication attempt runs and which are not re-checked on partial success. It also still makes public key queries fail before the client produces a signature when PublicKeyCallback supplies the restriction. Fixes CVE-2026-56854 Fixes golang/go#80213 Change-Id: Ibd612a8e4240bd710e33754f3ceb95bb29169d9a Reviewed-on: https://go-review.googlesource.com/c/crypto/+/797040 Reviewed-by: Junyang Shao <shaojunyang@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Filippo Valsorda <filippo@golang.org> Reviewed-by: David Chase <drchase@google.com>
This repository holds supplementary Go cryptography packages.
This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://go.dev/doc/contribute.
The git repository is https://go.googlesource.com/crypto.
The main issue tracker for the crypto repository is located at https://go.dev/issues. Prefix your issue with “x/crypto:” in the subject line, so it is easy to find.
Note that contributions to the cryptography package receive additional scrutiny due to their sensitive nature. Patches may take longer than normal to receive feedback.