openbsd
12 known vulnerabilities affecting openbsd products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-35385 | Medium | 0.6% | 7.5 | In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setg… | |
| CVE-2025-26465 | Low | 7.7% | 6.8 | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled… | |
| CVE-2026-55654 | Low | 0.4% | 3.7 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occu… | |
| CVE-2026-35386 | Low | 0.3% | 3.6 | In OpenSSH before 10.3, command execution can occur via shell metacharacters in … | |
| CVE-2026-55653 | Low | 0.3% | 4.3 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vu… | |
| CVE-2026-35387 | Low | 0.2% | 3.1 | OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA al… | |
| CVE-2026-35414 | Low | 0.2% | 4.2 | OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon… | |
| CVE-2026-73282 | Low | 0.2% | 4.8 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a … | |
| CVE-2026-73281 | Low | 0.2% | 3.5 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were… | |
| CVE-2026-35388 | Low | 0.1% | 2.5 | OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode mu… | |
| CVE-2026-73283 | Low | 0.1% | 2.5 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was su… | |
| CVE-2026-55655 | Low | 0.1% | 5.0 | A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client hos… |