The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Upstream bug: https://github.com/golang/go/issues/19767 Upstream patch: https://github.com/golang/crypto/commit/e4e2799dd7aab89f583e1d898300d96367750991
Created golang tracking bugs for this issue: Affects: epel-6 [bug 1439752] Affects: fedora-all [bug 1439751]