SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
https://pkg.go.dev/vuln/GO-2025-4135
https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA
https://go.dev/issue/76364
https://go.dev/cl/721960
Source: Mitre, NVD
Published: 2025-11-19
Updated: 2025-11-21
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P
Severity: Medium
Base Score: 5.3
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS: 0.00039