CVE-2026-39835 affects multiple packages. SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. See references for individual vulnerability details.