Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-59995

Опубликовано: 09 июл. 2026
Источник: msrc
CVSS3: 4.2
EPSS Низкий

Описание

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

EPSS

Процентиль: 17%
0.0025
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 5.4
redhat
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
nvd
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

CVSS3: 4.2
debian
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location o ...

CVSS3: 4.2
github
25 дней назад

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

EPSS

Процентиль: 17%
0.0025
Низкий

4.2 Medium

CVSS3