CLEANSTART-2026-XF15574
Dashboard / Vulnerabilities / CLEANSTART-2026-XF15574
Summary: source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2...
Details: Security vulnerability affects the octo-sts package. The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-XF15574.json, https://osv.dev/vulnerability/CVE-2026-56854, https://nvd.nist.gov/vuln/detail/CVE-2026-56854
Affected packages
Package
Name: octo-sts
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
