|
Identifier
|
Related Record |
Severity
|
Date Published
|
Description | Versions Affected |
|---|---|---|---|---|---|
| CVE-2026-60002 | Critical | Jul 08, 2026 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the clie more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
|
| CVE-2026-60001 | Medium | Jul 08, 2026 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
|
| CVE-2026-60000 | High | Jul 08, 2026 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
|
| CVE-2026-59999 | High | Jul 08, 2026 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
|
| CVE-2026-59998 | Medium | Jul 08, 2026 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active D more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
|
| CVE-2026-59997 | Medium | Jul 08, 2026 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argumen more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
|
| CVE-2026-59996 | Medium | Jul 08, 2026 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
|
| CVE-2026-59995 | Medium | Jul 08, 2026 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
|
| CVE-2026-35414 | BDSA-2026-7654 | High | Apr 02, 2026 | OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificat more... |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|
| CVE-2026-35388 | BDSA-2026-8035 | Low | Apr 02, 2026 | OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions. |
10.2, 9.8, 9.7, 9.5, 9.2, 8.9, 8.8, 7.7, 7.2, 7.1
|