CVE-2026-35387
בינונית 6.5
תיאור (מקור, אנגלית)
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-27/7/2026
- CWE
- CWE-670
מוצרים מושפעים
openbsd: openssh
קישורים
- https://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2 Third Party Advisory
- https://www.openssh.org/releasenotes.html#10.3p1 Release Notes
- https://www.openwall.com/lists/oss-security/2026/04/02/3 Third Party Advisory