|
Identifier
|
Related Record |
Severity
|
Date Published
|
Description | Versions Affected |
|---|---|---|---|---|---|
| CVE-2026-73283 | BDSA-2026-26987 | Low | Aug 11, 2026 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-73282 | BDSA-2026-26988 | Medium | Aug 11, 2026 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-73281 | BDSA-2026-26986 | Low | Aug 11, 2026 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens o more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-60002 | BDSA-2026-18347 | Critical | Jul 08, 2026 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the clie more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-60001 | BDSA-2026-18333 | Medium | Jul 08, 2026 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-60000 | BDSA-2026-18349 | High | Jul 08, 2026 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-59999 | BDSA-2026-18348 | High | Jul 08, 2026 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-59998 | BDSA-2026-18317 | Medium | Jul 08, 2026 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active D more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-59997 | BDSA-2026-18336 | Medium | Jul 08, 2026 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argumen more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-59996 | BDSA-2026-18334 | Medium | Jul 08, 2026 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|