CVE-2026-59996
- EPSS 0.25%
- Veröffentlicht 08.07.2026 00:07:07
- Zuletzt bearbeitet 09.07.2026 17:14:27
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CVE-2026-59995
- EPSS 0.25%
- Veröffentlicht 08.07.2026 00:04:49
- Zuletzt bearbeitet 09.07.2026 17:14:47
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CVE-2026-55654
- EPSS 0.43%
- Veröffentlicht 23.06.2026 03:37:00
- Zuletzt bearbeitet 24.09.2026 23:17:11
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators...
CVE-2026-55655
- EPSS 0.09%
- Veröffentlicht 23.06.2026 03:36:25
- Zuletzt bearbeitet 07.10.2026 03:16:59
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-...
CVE-2026-55653
- EPSS 0.29%
- Veröffentlicht 23.06.2026 03:36:22
- Zuletzt bearbeitet 07.10.2026 03:16:59
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when...
CVE-2026-35414
- EPSS 0.18%
- Veröffentlicht 02.04.2026 17:08:15
- Zuletzt bearbeitet 24.07.2026 21:10:00
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
CVE-2026-35388
- EPSS 0.13%
- Veröffentlicht 02.04.2026 16:57:31
- Zuletzt bearbeitet 24.07.2026 21:10:00
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-35387
- EPSS 0.24%
- Veröffentlicht 02.04.2026 16:52:53
- Zuletzt bearbeitet 24.07.2026 21:10:00
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
CVE-2026-35386
- EPSS 0.32%
- Veröffentlicht 02.04.2026 16:44:27
- Zuletzt bearbeitet 24.07.2026 21:10:00
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh...
CVE-2026-35385
- EPSS 0.61%
- Veröffentlicht 02.04.2026 16:30:59
- Zuletzt bearbeitet 01.09.2026 13:19:01
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).