CVE-2026-35388
נמוכה 2.5
תיאור (מקור, אנגלית)
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
מדדים
- CVSS 3.1
-
2.5 (LOW)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-27/7/2026
- CWE
- CWE-420
מוצרים מושפעים
openbsd: openssh
קישורים
- https://marc.info/?l=openssh-unix-dev&m=177513443901484&w=2 Third Party Advisory
- https://www.openssh.org/releasenotes.html#10.3p1 Release Notes
- https://www.openwall.com/lists/oss-security/2026/04/02/3 Third Party Advisory