Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-35386

Опубликовано: 02 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 3.6

Описание

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

РелизСтатусПримечание
devel

pending

1:10.2p1-2ubuntu3.2
esm-infra-legacy/trusty

needs-triage

esm-infra-legacy/xenial

not-affected

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

esm-infra/xenial

ignored

end of ESM support, was needs-triage
fips-preview/jammy

needed

fips-updates/bionic

needs-triage

fips-updates/focal

needs-triage

fips-updates/jammy

released

1:8.9p1-3ubuntu0.15+Fips1

Показывать по

РелизСтатусПримечание
devel

ignored

esm-apps/bionic

ignored

esm-apps/focal

ignored

esm-apps/jammy

ignored

esm-apps/noble

ignored

esm-apps/resolute

ignored

jammy

ignored

noble

ignored

questing

ignored

resolute

ignored

Показывать по

EPSS

Процентиль: 16%
0.00247
Низкий

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 3.6
redhat
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
nvd
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
msrc
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

CVSS3: 3.6
debian
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metachar ...

CVSS3: 3.6
github
4 месяца назад

In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This requires a scenario where the username on the command line is untrusted, and also requires a non-default configurations of % in ssh_config.

EPSS

Процентиль: 16%
0.00247
Низкий

3.6 Low

CVSS3