Known Vulnerabilities for OpenSSH by OpenBSD
Listed below are 10 of the newest known vulnerabilities associated with "OpenSSH" by "OpenBSD".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55655 json | A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding conne... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-55654 json | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Secu... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-55653 json | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Excha... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-48108 json | Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the S... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-39832 json | When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in... | Not Provided | 2026-05-22 | 2026-05-22 |
| CVE-2026-39831 json | The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not ... | Not Provided | 2026-05-22 | 2026-05-22 |
| CVE-2026-35414 json | OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in con... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-35388 json | OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions. | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-35387 json | OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or Hostba... | Not Provided | 2026-04-02 | 2026-04-03 |
| CVE-2026-35386 json | In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requir... | Not Provided | 2026-04-02 | 2026-04-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openbsd | Openssh | 8.4 | |||
| Application | Openbsd | Openssh | 8.4 | |||
| Application | Openbsd | Openssh | 8.3 | |||
| Application | Openbsd | Openssh | 8.3 | |||
| Application | Openbsd | Openssh | 8.3 | |||
| Application | Openbsd | Openssh | 8.2 | |||
| Application | Openbsd | Openssh | 8.1 | |||
| Application | Openbsd | Openssh | 8.1 | |||
| Application | Openbsd | Openssh | 8.0 | |||
| Application | Openbsd | Openssh | 8.0 | |||
| Application | Openbsd | Openssh | 7.9 | |||
| Application | Openbsd | Openssh | 7.9 | |||
| Application | Openbsd | Openssh | 7.8 | |||
| Application | Openbsd | Openssh | 7.8 | |||
| Application | Openbsd | Openssh | 7.7 | |||
| Application | Openbsd | Openssh | 7.7 | |||
| Application | Openbsd | Openssh | 7.6 | |||
| Application | Openbsd | Openssh | 7.6 | |||
| Application | Openbsd | Openssh | 7.5 | |||
| Application | Openbsd | Openssh | 7.5 |