Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35414

Опубликовано: 02 апр. 2026
Источник: debian
EPSS Низкий

Описание

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensshfixed1:10.3p1-1package
opensshfixed1:10.0p1-7+deb13u3trixiepackage
opensshfixed1:9.2p1-2+deb12u10bookwormpackage

Примечания

  • https://www.openssh.org/releasenotes.html#10.3p1

EPSS

Процентиль: 7%
0.00176
Низкий

Связанные уязвимости

CVSS3: 4.2
ubuntu
4 месяца назад

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

CVSS3: 4.8
redhat
4 месяца назад

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

CVSS3: 4.2
nvd
4 месяца назад

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

msrc
4 месяца назад

Описание отсутствует

CVSS3: 4.2
github
4 месяца назад

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

EPSS

Процентиль: 7%
0.00176
Низкий