Search CVE reports


Toggle filters

1 – 10 of 94 results


CVE-2026-35414

Medium priority
Needs evaluation

(OpenSSH before 10.3 mishandles the authorized_keys principals option i ...)

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35388

Medium priority
Needs evaluation

(OpenSSH before 10.3 omits connection multiplexing confirmation for pro ...)

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35387

Medium priority
Needs evaluation

(OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of an ...)

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35386

Medium priority
Needs evaluation

(In OpenSSH before 10.3, command execution can occur via shell metachar ...)

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35385

Medium priority
Needs evaluation

(In OpenSSH before 10.3, a file downloaded by scp may be installed setu ...)

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Needs evaluation Needs evaluation Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-3497

Medium priority

Some fixes available 4 of 9

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The...

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Not affected
openssh-ssh1 Ignored Ignored Ignored Ignored
Show less packages

CVE-2025-61985

Low priority

Some fixes available 4 of 11

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Not affected
openssh-ssh1 Ignored Ignored Ignored Ignored
Show less packages

CVE-2025-61984

Low priority

Some fixes available 4 of 14

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command...

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Vulnerable
openssh-ssh1 Ignored Ignored Ignored Ignored
Show less packages

CVE-2025-32728

Medium priority

Some fixes available 6 of 14

In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Vulnerable
openssh-ssh1 Ignored Ignored Needs evaluation Needs evaluation
Show less packages

CVE-2025-26466

Medium priority
Fixed

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has...

2 affected packages

openssh, openssh-ssh1

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Not affected Not affected Not affected
openssh-ssh1 Not affected Not affected Not affected Not affected
Show less packages