CVE-2025-47913: Potential denial of service in golang.org/x/crypto/ssh/agent
Published Nov 13, 2025
·Updated
Potential denial of service in golang.org/x/crypto/ssh/agent
Other sources
SSH clients receiving SSHAGENTSUCCESS when expecting a typed response will panic and cause early termination of the client process.
— NVD
Affected Software
13 affected componentsFixes available
Golang x/crypto/ssh/agent
Microsoft azl3 packer 1.9.5-10
Microsoft azl3 docker-buildx 0.14.0-7
Microsoft azl3 docker-compose 2.27.0-5
Microsoft azl3 kubevirt 1.5.0-5
Microsoft azl3 telegraf 1.31.0-10
Microsoft cbl2 packer 1.9.5-15
Microsoft cbl2 moby-compose 2.17.3-11
go Ssh Go<0.43.0
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1
Remediation
Patch Available
Event History
Nov 13, 2025
CVE Published
via MITRE·09:29 PM
Data Sourced
via MITRE·09:29 PM
DescriptionWeakness
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 17, 2025
Data Sourced
via Microsoft·01:02 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:02 AM
Affected Software
Updated
via Microsoft·01:02 AM
DescriptionSeverity
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-47913?
CVE-2025-47913 is considered a high severity vulnerability due to the potential for client process termination.
2
How do I fix CVE-2025-47913?
To mitigate CVE-2025-47913, upgrade to the latest version of Golang x/crypto/ssh/agent where the issue has been resolved.
3
What systems are affected by CVE-2025-47913?
CVE-2025-47913 affects SSH clients utilizing Golang's x/crypto/ssh/agent for handling agent responses.
4
What impact does CVE-2025-47913 have on users?
Users of affected SSH clients may experience unexpected client crashes due to the vulnerability.
5
Is there a workaround for CVE-2025-47913?
Currently, the recommended solution is to update the affected software, as no workaround is provided.