Search CVE reports


Toggle filters

21 – 30 of 119 results


CVE-2026-59996

Medium priority

Some fixes available 3 of 10

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Not affected Not affected
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-59995

Medium priority

Some fixes available 7 of 14

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Fixed Fixed
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-55655

Medium priority
Ignored

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is...

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Not affected Not affected Not affected Not affected Not affected
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-55654

Low priority
Ignored

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in...

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Not affected Not affected Not affected Not affected Not affected
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-55653

Medium priority
Needs evaluation

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode...

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Not affected Not affected Not affected Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35414

Medium priority

Some fixes available 8 of 14

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Fixed Fixed
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35388

Medium priority

Some fixes available 4 of 14

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Needs evaluation Needs evaluation
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35387

Medium priority

Some fixes available 8 of 14

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Fixed Fixed
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35386

Medium priority

Some fixes available 5 of 11

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default...

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Not affected Not affected
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2026-35385

Medium priority

Some fixes available 8 of 14

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

2 affected packages

openssh, openssh-ssh1

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openssh Fixed Fixed Fixed Fixed Fixed
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
Show less packages