Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59995

Опубликовано: 08 июл. 2026
Источник: debian
EPSS Низкий

Описание

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensshfixed1:10.4p1-1package
opensshno-dsatrixiepackage
opensshpostponedbookwormpackage
opensshpostponedbullseyepackage

Примечания

  • https://www.openssh.org/releasenotes.html#10.4p1

EPSS

Процентиль: 17%
0.0025
Низкий

Связанные уязвимости

CVSS3: 4.2
ubuntu
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 5.4
redhat
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
nvd
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
msrc
24 дня назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
github
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

EPSS

Процентиль: 17%
0.0025
Низкий