Skip to main content
Version: v1.2.x

CVE-2026-39827

CVE Details

Visit the official vulnerability details page for CVE-2026-39827 to learn more.

Initial Publication

05/22/2026

Last Update

07/23/2026

Third Party Dependency

golang.org/x/crypto

NIST CVE Summary

An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.

CVE Severity

6.5

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.2.1⚠️ Impacted⚠️ Impacted
1.1.8⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.