OSV 1.4.0 · unreviewed · 修改于 2026-08-29 08:30
发布时间
2026-08-29 02:31
GitHub 审查时间
—
NVD 发布时间
2026-08-29 00:18
源文件
advisories/unreviewed/2026/08/GHSA-gjhq-gjfw-99mq/GHSA-gjhq-gjfw-99mq.json
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.
该公告没有提供结构化的受影响软件包信息。