Openssh
This hub aggregates every CVE we track for Openssh, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
140
CVEs tracked
13
Critical
47
High
0
In CISA KEV
Severity distribution
MEDIUM64HIGH47LOW16CRITICAL13
Monthly trend
0
0
0
0
0
2
0
1
0
0
0
1
0
2
0
0
0
0
1
5
0
3
8
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Openssh.
- CVE-2026-60002ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)7.7
- CVE-2026-60001sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.6.5
- CVE-2026-60000sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthenti...3.7
- CVE-2026-59999In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.5.9
- CVE-2026-59998sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.4.8
- CVE-2026-59997internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended sec...4.2
- CVE-2026-59996scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.4.2
- CVE-2026-59995sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.4.2
- CVE-2026-55654Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination3.7
- CVE-2026-55655Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions5.0
- CVE-2026-55653Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service4.3
- CVE-2026-35414OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma ch...4.2
- CVE-2026-35388OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.2.5
- CVE-2026-35387OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.3.1
- CVE-2026-35386In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and a...3.6
Product normalization is registry-driven with AI assist and human review. How it works