Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35386

Опубликовано: 02 апр. 2026
Источник: nvd
CVSS3: 3.6
CVSS3: 8.1
EPSS Низкий

Описание

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Версия от 10.0 (включая) до 10.3 (исключая)

EPSS

Процентиль: 24%
0.00319
Низкий

3.6 Low

CVSS3

8.1 High

CVSS3

Дефекты

CWE-696

Связанные уязвимости

CVSS3: 3.6
ubuntu
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
redhat
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
msrc
4 месяца назад

Описание отсутствует

CVSS3: 3.6
debian
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metachar ...

CVSS3: 3.6
github
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

EPSS

Процентиль: 24%
0.00319
Низкий

3.6 Low

CVSS3

8.1 High

CVSS3

Дефекты

CWE-696