FlawAtlas
Search the atlas
CVE-2024-39223 Critical

Missing key verification in gost in github.com/ginuerzh/gost

Missing key verification in gost in github.com/ginuerzh/gost

Exploit probability 0.7%
Published October 28, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/ginuerzh/gost
Go github.com/ginuerzh/gost

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-8wxx-35qc-vp6r

An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey

View original source

05 / REFERENCES

Further evidence