ZeroHour

CVE-2026-35387

CVSS 3.1
6.5 medium
EPSS
<1%p15
Published
()
Modified
Description

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.

Vendors
openbsd
Products
openssh
Weakness
CWE-670
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news