← Back to feed Search feed

OpenSSH vulnerabilities

15 entries matching openssh — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-60002ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This HIGH7.722%ileMicrosoft2026-07-14
CVE-2026-60001sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.MEDIUM6.521%ileMicrosoft2026-07-14
CVE-2026-59999In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did notMEDIUM5.96%ileMicrosoft2026-07-14
CVE-2026-59998sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if thMEDIUM4.88%ileMicrosoft2026-07-14
CVE-2026-59997internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important MEDIUM4.27%ileMicrosoft2026-07-14
CVE-2026-59996scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betweeMEDIUM4.216%ileMicrosoft2026-07-14
CVE-2026-59995sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is uMEDIUM4.216%ileMicrosoft2026-07-14
CVE-2026-60000sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive auLOW3.736%ileMicrosoft2026-07-14
CVE-2026-55655Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client veMEDIUM5.00%ileMicrosoft2026-06-09
CVE-2026-55653Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validatiMEDIUM4.321%ileMicrosoft2026-06-09
CVE-2026-35385CVE-2026-35385HIGH7.546%ileMicrosoft2026-04-14
CVE-2026-35414CVE-2026-35414MEDIUM4.27%ileMicrosoft2026-04-14
CVE-2026-35386CVE-2026-35386LOW3.624%ileMicrosoft2026-04-14
CVE-2026-35387CVE-2026-35387LOW3.115%ileMicrosoft2026-04-14
CVE-2026-35388CVE-2026-35388LOW2.53%ileMicrosoft2026-04-14