Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pjcq-xvwq-hhpj | go-ntlmssp NTLM challenges can panic on malformed payloads |
Thu, 30 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Azure
Azure go-ntlmssp |
|
| Vendors & Products |
Azure
Azure go-ntlmssp |
Fri, 24 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue. | |
| Title | go-ntlmssp NTLM challenges can panic on malformed payloads | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-24T16:29:28.264Z
Reserved: 2026-03-17T00:05:53.285Z
Link: CVE-2026-32952
Updated: 2026-04-24T16:29:24.621Z
Status : Awaiting Analysis
Published: 2026-04-24T03:16:07.833
Modified: 2026-04-24T14:50:56.203
Link: CVE-2026-32952
OpenCVE Enrichment
Updated: 2026-04-28T09:25:25Z
Github GHSA