CVE-2026-56854 (High) detected in golang.org/x/crypto-v0.49.0
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 85/100
Research direction
Start with /engine/go.mod and inspect the golang.org/x/crypto dependency currently pinned at v0.49.0. Update it to the reported fixed version v0.55.0, then verify that the dependency resolves successfully and the project's Go checks pass.
Written by the indexing model from the issue text.
Description
CVE-2026-56854 - High Severity Vulnerability
Vulnerable Library - golang.org/x/crypto-v0.49.0
Library home page: https://proxy.golang.org/golang.org/x/crypto/@v/v0.49.0.zip
Sample Path to Dependency File: /engine/go.mod
Path to vulnerable library: /home/wss-scanner/go/pkg/mod/cache/download/golang.org/x/crypto/@v/v0.49.0.mod
Dependency Hierarchy:
- ❌ golang.org/x/crypto-v0.49.0 (Vulnerable Library)
Found in base branch: master
Vulnerability Details
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.
Publish Date: 2026-08-28
URL: CVE-2026-56854
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://pkg.go.dev/vuln/GO-2026-6303
Release Date: 2026-08-28
Fix Resolution: golang.org/x/crypto - v0.55.0
Step up your Open Source Security Game with Mend here
- Dominant language
- Go
- Stars
- 2.7k
- Forks
- 85
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from postgres-ai/database-lab-engine
-
Mend: dependency security vulnerability
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Mend: dependency security vulnerability
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Mend: dependency security vulnerability
Difficulty 1/5 Under an hour Newbie friendliness 86/100
-
Mend: dependency security vulnerability
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Mend: dependency security vulnerability
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
All issues in postgres-ai/database-lab-engine
Similar issues
-
bug(hub,chat): Wave-2 web chat sendAgentRouted does not update RecordChannel reply affinity to 'web'Open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
GoogleCloudPlatform/scion#2448 ·
Maintainers usually reply within 1 day
-
customer issue
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
dolthub/go-mysql-server#3988 ·
Maintainers usually reply within 1 day
-
bug keploy
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
grpc/grpc-go#9481 · 1 comment ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
SocialGouv/iterion#2195 ·
Maintainers usually reply within 1 day