Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35414

Опубликовано: 02 апр. 2026
Источник: nvd
CVSS3: 4.2
CVSS3: 8.1
EPSS Низкий

Описание

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Версия до 10.3 (исключая)

EPSS

Процентиль: 7%
0.00176
Низкий

4.2 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-670

Связанные уязвимости

CVSS3: 4.2
ubuntu
4 месяца назад

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

CVSS3: 4.8
redhat
4 месяца назад

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

CVSS3: 4.2
msrc
4 месяца назад

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

CVSS3: 4.2
debian
4 месяца назад

OpenSSH before 10.3 mishandles the authorized_keys principals option i ...

CVSS3: 4.2
github
4 месяца назад

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

EPSS

Процентиль: 7%
0.00176
Низкий

4.2 Medium

CVSS3

8.1 High

CVSS3

Дефекты

CWE-670