⌘K

CVE-2024-45337

Go crypto/ssh — authorization bypass via ServerConfig.PublicKeyCallback

First detected

Feb 25, 2026, 12:54 PM

Last detected

Apr 24, 2026, 1:53 PM

Open

Base score

9.9

Critical

Sweet score parameters

+2.8

Runtime Utilization

reachability

+2.1

Public Facing

exposure

+1

Exploit in the Wild

EPSS / KEV

+1.2

Workload Exploitation

behavior

Sweet score

9.9

↑ 0.8

Adjusted by OnDuty AI for your environment

Sweet score reasoning

AI · gpt-onduty-soc · 380 ms

Reachable code path is loaded and executed in production. The workload accepts inbound SSH from a public load balancer and the package version is vulnerable. EPSS trending up over the last 7 days.

Technical impact

Successful exploitation can allow an unauthenticated attacker to bypass SSH authorization and execute commands as a privileged service identity.

Graph

ec2

golang.org/x/crypto

CVE-2024-45337

Auth bypass