OpenBSD / OpenSSH
138 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-73283 | openssh: OpenSSH: Tunnel forwarding restriction bypass | MEDIUM | 5.4 | Aug 11, 2026 |
| CVE-2026-73282 | openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client | MEDIUM | 5.6 | Aug 11, 2026 |
| CVE-2026-73281 | openssh: OpenSSH: ssh-agent allows remote execution of local operations | LOW | 3.5 | Aug 11, 2026 |
| CVE-2026-60002 | openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side | CRITICAL | 9.4 | Jul 8, 2026 |
| CVE-2026-60001 | openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay | MEDIUM | 6.5 | Jul 8, 2026 |
| CVE-2026-60000 | openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts | HIGH | 7.5 | Jul 8, 2026 |
| CVE-2026-59999 | openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options | HIGH | 7.5 | Jul 8, 2026 |
| CVE-2026-59998 | openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory | MEDIUM | 6.5 | Jul 8, 2026 |
| CVE-2026-59997 | openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw | MEDIUM | 5.4 | Jul 8, 2026 |
| CVE-2026-59996 | openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy | MEDIUM | 5.4 | Jul 8, 2026 |
| CVE-2026-59995 | openssh: OpenSSH: sftp client allows attacker to control downloaded file location | MEDIUM | 5.4 | Jul 8, 2026 |
| CVE-2026-55654 | Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination | LOW | 3.7 | Jun 23, 2026 |
| CVE-2026-55655 | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions | MEDIUM | 6.1 | Jun 23, 2026 |
| CVE-2026-55653 | Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of servi… | MEDIUM | 6.5 | Jun 23, 2026 |
| CVE-2026-35414 | OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option | HIGH | 8.1 | Apr 2, 2026 |
| CVE-2026-35388 | OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions | LOW | 2.5 | Apr 2, 2026 |
| CVE-2026-35387 | OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage | MEDIUM | 6.5 | Apr 2, 2026 |
| CVE-2026-35386 | OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username | HIGH | 8.1 | Apr 2, 2026 |
| CVE-2026-35385 | OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode | HIGH | 8.1 | Apr 2, 2026 |
| CVE-2026-3497 | openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables | MEDIUM | 6.9 | Mar 12, 2026 |
| CVE-2025-61985 | openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand | MEDIUM | 5.3 | Oct 6, 2025 |
| CVE-2025-61984 | openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand | MEDIUM | 5.3 | Oct 6, 2025 |
| CVE-2025-32728 | openssh: OpenSSH SSHD Agent Forwarding and X11 Forwarding | MEDIUM | 4.3 | Apr 10, 2025 |
| CVE-2025-26466 | Openssh: denial-of-service in openssh | MEDIUM | 5.9 | Feb 28, 2025 |
| CVE-2025-26465 | Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled | MEDIUM | 6.8 | Feb 18, 2025 |
Showing 1 to 25 of 138 CVEs