Known Vulnerabilities for products from OpenBSD
Listed below are 20 of the newest known vulnerabilities associated with the vendor "OpenBSD".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73283 json | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding ... | Not Provided | 2026-08-11 | 2026-09-04 |
| CVE-2026-73282 json | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations ... | Not Provided | 2026-08-11 | 2026-09-04 |
| CVE-2026-73281 json | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including op... | Not Provided | 2026-08-11 | 2026-09-04 |
| CVE-2026-60002 json | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outco... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-60001 json | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-60000 json | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authent... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59999 json | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59998 json | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the ser... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59997 json | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a ... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59996 json | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59995 json | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used w... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-57589 json | Not Provided | 2026-06-25 | 2026-06-26 | |
| CVE-2026-56101 json | Not Provided | 2026-09-08 | 2026-09-08 | |
| CVE-2026-56099 json | OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within ... | Not Provided | 2026-06-18 | 2026-07-14 |
| CVE-2026-55706 json | sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for le... | Not Provided | 2026-06-17 | 2026-07-13 |
| CVE-2026-55655 json | A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding conne... | Not Provided | 2026-06-23 | 2026-09-01 |
| CVE-2026-55654 json | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Secu... | Not Provided | 2026-06-23 | 2026-09-01 |
| CVE-2026-55653 json | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Excha... | Not Provided | 2026-06-23 | 2026-09-01 |
| CVE-2026-41285 json | In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discover... | Not Provided | 2026-04-21 | 2026-04-24 |
| CVE-2026-35414 json | OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in con... | Not Provided | 2026-04-02 | 2026-07-24 |