CVE-2026-53495: containerd: CRI ExecSync goroutine leak can lead to node-level denial of service (bsc#1280111).
CVE-2026-56854: golang.org/x/crypto/ssh: unenforced source-address restrictions across non-public-key authentication
callbacks can cause authorization bypasses and unauthorized client logins (bsc#1278624).
CVE-2026-56855: golang.org/x/crypto/ssh: unhandled RFC 4254 channel messages can cause connection deadlocks and
denial of service (bsc#1278624).
CVE-2026-78662: golang.org/x/crypto/ssh: unvalidated incoming requests on unestablished channels can cause connection
deadlocks and denial of service (bsc#1278624).