Skip to main content
Version: v1.1.x

CVE-2026-39832

CVE Details

Visit the official vulnerability details page for CVE-2026-39832 to learn more.

Initial Publication

05/22/2026

Last Update

07/14/2026

Third Party Dependency

golang.org/x/crypto

NIST CVE Summary

When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.

CVE Severity

9.1

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Modified

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.1.8⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.