CVE-2026-32952 PUBLISHED

go-ntlmssp NTLM challenges can panic on malformed payloads

Assigner: GitHub_M
Reserved: 17.03.2026 Published: 24.04.2026 Updated: 24.04.2026

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using ntlmssp.Negotiator as an HTTP transport. Version 0.1.1 patches the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 5.3

Product Status

Vendor Azure
Product go-ntlmssp
Versions
  • Version < 0.1.1 is affected

References

Problem Types

  • CWE-190: Integer Overflow or Wraparound CWE