Openbsd

Openssh

152 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.13%
  • Veröffentlicht 06.10.2026 23:42:14
  • Zuletzt bearbeitet 07.10.2026 14:47:21

In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line username, leading to injection.

  • EPSS 0.08%
  • Veröffentlicht 06.10.2026 21:21:35
  • Zuletzt bearbeitet 07.10.2026 16:17:44

In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support ...

  • EPSS 0.13%
  • Veröffentlicht 06.10.2026 21:10:00
  • Zuletzt bearbeitet 07.10.2026 15:17:18

In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.

  • EPSS 0.08%
  • Veröffentlicht 06.10.2026 21:01:44
  • Zuletzt bearbeitet 07.10.2026 14:47:21

In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled.

  • EPSS 0.08%
  • Veröffentlicht 06.10.2026 20:57:09
  • Zuletzt bearbeitet 07.10.2026 17:16:52

In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.

  • EPSS 0.19%
  • Veröffentlicht 06.10.2026 20:52:39
  • Zuletzt bearbeitet 07.10.2026 14:47:21

In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data.

  • EPSS 0.06%
  • Veröffentlicht 06.10.2026 20:47:50
  • Zuletzt bearbeitet 07.10.2026 17:16:52

In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.

  • EPSS 0.18%
  • Veröffentlicht 06.10.2026 20:35:32
  • Zuletzt bearbeitet 07.10.2026 15:17:18

In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings.

  • EPSS 0.08%
  • Veröffentlicht 06.10.2026 20:28:56
  • Zuletzt bearbeitet 07.10.2026 14:47:21

In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can incorrectly be persisted across authentication attempts.

  • EPSS 0.08%
  • Veröffentlicht 06.10.2026 20:25:45
  • Zuletzt bearbeitet 07.10.2026 17:16:50

In sshd in OpenSSH before 10.6, credentials can incorrectly persist after failure of a GSSAPIAuthentication authentication attempt.