Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-9283

47
FAUCET Score

CVE-2020-9283 is a high-severity denial-of-service vulnerability affecting the golang.org/x/crypto/ssh package in Go, specifically versions before v0.0.0-20200220183623-bac4c82f6975, as well as Debian and Go SSH packages. This flaw allows a remote attacker to trigger a panic during signature verification, impacting both SSH clients and servers. With a CVSS score of 7.5 (High), it presents a low-complexity attack vector with no user interaction required, leading to a complete denial of service. While not actively exploited in the wild and not on the KEV catalog, a proof-of-concept exploit (EDB-48121) is publicly available, though there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
0.0.0-20200220183623-bac4c82f6975CPE matchmatch criteria
cpe:2.3:a:golang:package_ssh:0.0.0-20200220183623-bac4c82f6975:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
21.05%
Probability of exploitation in next 30 days
EPSS Percentile
97.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-48121 · Feb 24, 2020
This CVE's current EPSS score of 0.2105 is in the 96th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (86)

gopatch availablevia ghsa
Product: golang.org/x/cryptoFixed in: 0.0.0-20200220183623-bac4c82f6975
redhatpatch availablevia redhat_api
Product: Jaeger-1.17Fixed in: distributed-tracing/jaeger-query-rhel7:1.17.6-1
View patch
redhatpatch availablevia redhat_api
Product: Jaeger-1.17Fixed in: distributed-tracing/jaeger-rhel7-operator:1.17.6-1
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: openshift-service-mesh/3scale-istio-adapter-rhel8:1.0.0-8
View patch
redhatpatch availablevia redhat_api
Product: Openshift Service Mesh 1.1Fixed in: kiali-0:v1.12.10.redhat2-1.el7
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.1Fixed in: ior-0:1.1.6-1.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.1Fixed in: servicemesh-0:1.1.6-1.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.1Fixed in: servicemesh-cni-0:1.1.6-1.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.1Fixed in: servicemesh-grafana-0:6.4.3-13.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.1Fixed in: servicemesh-operator-0:1.1.6-2.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.1Fixed in: servicemesh-prometheus-0:2.14.0-14.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.3Fixed in: openshift-clients-0:4.3.31-202007250052.p0.git.3329.59998b9.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.6Fixed in: openshift4/ose-elasticsearch-operator:v4.6.0-202010200139.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift4/ose-descheduler:v4.5.0-202007101023.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift4/ose-cluster-kube-descheduler-operator:v4.5.0-202007131801.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift-0:4.5.0-202007012112.p0.git.0.582d7fc.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift4/ose-cluster-logging-operator:v4.5.0-202007012112.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.4Fixed in: openshift4/ose-cluster-machine-approver:v4.4.0-202007171809.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.4Fixed in: openshift4/ose-cloud-credential-operator:v4.4.0-202007060343.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.4Fixed in: openshift4/ose-descheduler:v4.4.0-202006290400.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.4Fixed in: openshift4/ose-azure-machine-controllers:v4.4.0-202006290400.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.4Fixed in: openshift4/ose-baremetal-rhel7-operator:v4.4.0-202006290400.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.3Fixed in: openshift4/ose-sriov-dp-admission-controller:v4.3.37-202009151447.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.3Fixed in: openshift4/ose-azure-machine-controllers:v4.3.31-202007272153.p0
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.10 on RHEL 7Fixed in: 3scale-amp2/3scale-rhel7-operator:1.13.0-17
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.10 on RHEL 7Fixed in: 3scale-amp2/3scale-rhel7-operator-metadata:2.10.0-38
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.10 on RHEL 7Fixed in: 3scale-amp2/apicast-rhel7-operator:1.13.0-4
View patch
redhatpatch availablevia redhat_api
Product: 3scale API Management 2.10 on RHEL 7Fixed in: 3scale-amp2/apicast-rhel7-operator-metadata:2.10.0-9
View patch
redhatpatch availablevia redhat_api
Product: Jaeger-1.17Fixed in: distributed-tracing/jaeger-agent-rhel7:1.17.6-1
View patch
redhatpatch availablevia redhat_api
Product: Jaeger-1.17Fixed in: distributed-tracing/jaeger-all-in-one-rhel7:1.17.6-1
View patch
redhatpatch availablevia redhat_api
Product: Jaeger-1.17Fixed in: distributed-tracing/jaeger-collector-rhel7:1.17.6-1
View patch
redhatpatch availablevia redhat_api
Product: Jaeger-1.17Fixed in: distributed-tracing/jaeger-es-index-cleaner-rhel7:1.17.6-1
View patch
redhatpatch availablevia redhat_api
Product: Jaeger-1.17Fixed in: distributed-tracing/jaeger-ingester-rhel7:1.17.6-1
View patch
redhatpatch availablevia redhat_api
Product: Jaeger-1.17Fixed in: distributed-tracing/jaeger-es-rollover-rhel7:1.17.6-1
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Storage 3Fixed in: heketi
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: kubevirt-metrics-collector
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: kubevirt-web-ui
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: kubevirt-web-ui-operator
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: multus-cni
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: ovs-cni-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: sriov-network-device-plugin
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: virt-api
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: virt-controller
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: virt-handler
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: virt-launcher
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: virt-operator
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-baremetal-installer-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-baremetal-machine-controllers-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-cluster-autoscaler
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-cluster-svcat-apiserver-operator
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-cluster-svcat-controller-manager-operator
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console-operator
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-descheduler-operator
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-installer
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-installer-artifacts
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-libvirt-machine-controllers
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-local-storage-static-provisioner
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-metering-helm-container-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-operator-marketplace-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-ptp
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-service-catalog
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift-enterprise-service-catalog
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: template-service-broker-container
redhatvendor investigatingvia redhat_api
Product: Red Hat Openshift Container Storage 4Fixed in: ocs4/cephcsi-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 1Fixed in: kubevirt-cpu-node-labeller
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-vertical-pod-autoscaler-rhel9-operator
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-cluster-capacity
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-operator
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-launcher
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-handler
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-controller
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-cdi-uploadserver
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-cdi-uploadproxy
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-cdi-operator
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-cdi-importer
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-cdi-controller
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-cdi-cloner
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-cdi-apiserver
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-api
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-vertical-pod-autoscaler-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: kubevirt-cpu-node-labeller
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-descheduler
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: golang-github-openshift-oauth-proxy
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift-enterprise-cluster-capacity
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-cluster-autoscaler

Vendor Advisories (2)

goGHSA-ffhg-7mh4-33c4high

Improper Verification of Cryptographic Signature in golang.org/x/crypto

May 18, 2021
redhatCVE-2020-9283Important

golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic

Feb 21, 2020

References

packetstormsecurity.com / files/156480/Go-SSH-0.0.2-Denial-Of-Service.html
ExploitThird Party AdvisoryVDB Entry
groups.google.com / forum
lists.debian.org / debian-lts-announce/2020/10/msg00014.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/11/msg00027.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2020/11/msg00031.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2023/06/msg00017.html