CVE-2024-45337
Go crypto/ssh — authorization bypass via ServerConfig.PublicKeyCallback
First detected
Feb 25, 2026, 12:54 PM
Last detected
Apr 24, 2026, 1:53 PM
Base score
9.9
Critical
Sweet score parameters
+2.8
Runtime Utilization
reachability
+2.1
Public Facing
exposure
+1
Exploit in the Wild
EPSS / KEV
+1.2
Workload Exploitation
behavior
Sweet score
9.9
↑ 0.8Adjusted by OnDuty AI for your environment
Sweet score reasoning
AI · gpt-onduty-soc · 380 msReachable code path is loaded and executed in production. The workload accepts inbound SSH from a public load balancer and the package version is vulnerable. EPSS trending up over the last 7 days.
Technical impact
Successful exploitation can allow an unauthenticated attacker to bypass SSH authorization and execute commands as a privileged service identity.
Graph
ec2
golang.org/x/crypto
CVE-2024-45337
Auth bypass