Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A critical flaw in the SSH agent component of golang.org/x/crypto silently drops key-level restrictions, such as use-confirmation prompts and lifetime limits, when forwarding SSH keys, leaving those keys available to anyone who can intercept or influence the forwarded agent session. Microsoft’s azl3 docker-buildx 0.14.0-11 package on Azure Linux 3.0 is the confirmed affected distribution, disclosed as part of May 2026 Patch Tuesday. Organizations using Azure Linux 3.0 container build pipelines with SSH agent forwarding enabled are exposed to unauthorized lateral movement using credentials that should have been constrained.

Author

Tech Jacks Solutions