Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59997

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

A flaw was found in OpenSSH. The internal-sftp component within sshd incorrectly processes command-line arguments, recognizing only the first nine. This limitation can prevent the application of intended security configurations for SFTP (SSH File Transfer Protocol) connections, potentially leading to a bypass of security properties.

Меры по смягчению последствий

To mitigate this issue, ensure that all security-relevant command-line arguments for the internal-sftp server are positioned within the first nine arguments. Alternatively, consider using the default SFTP server implementation if custom configurations relying on numerous arguments are not strictly necessary. If internal-sftp is used with more than nine arguments, verify that no critical security options are being silently discarded.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshFix deferred
Red Hat Enterprise Linux 6opensshFix deferred
Red Hat Enterprise Linux 7opensshFix deferred
Red Hat Enterprise Linux 8opensshFix deferred
Red Hat Enterprise Linux 9opensshFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Hardened Imagesopenssh-main-10.4p1-1.hum1FixedRHSA-2026:3738209.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2497929openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw

EPSS

Процентиль: 7%
0.00175
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
25 дней назад

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

CVSS3: 4.2
nvd
25 дней назад

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

CVSS3: 4.2
msrc
24 дня назад

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

CVSS3: 4.2
debian
25 дней назад

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first ...

CVSS3: 4.2
github
25 дней назад

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

EPSS

Процентиль: 7%
0.00175
Низкий

5.4 Medium

CVSS3