<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:07:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:69129 — Important: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:69129</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssh, AlmaLinux:10: openssh-askpass, AlmaLinux:10: openssh-clients, AlmaLinux:10: openssh-keycat, AlmaLinux:10: openssh-keysign, AlmaLinux:10: openssh-server&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)
  * openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)
  * openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)
  * openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)
  * openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssh, AlmaLinux:10: openssh-askpass, AlmaLinux:10: openssh-clients, AlmaLinux:10: openssh-keycat, AlmaLinux:10: openssh-keysign, AlmaLinux:10: openssh-server&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)
  * openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)
  * openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)
  * openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)
  * openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:69129</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-73282</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-73282</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:25: openssh, BellSoft Hardened Containers:stream: openssh&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: openssh, Alpaquita:stream: openssh, BellSoft Hardened Containers:25: openssh, BellSoft Hardened Containers:stream: openssh&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-73282</guid>
    </item>
    <item>
      <title>EUVD-2026-351278</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351278</link>
      <description>EUVD-2026-351278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351278</guid>
    </item>
    <item>
      <title>fkie_cve-2026-73282</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73282</link>
      <description>&lt;p&gt;In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-73282</guid>
    </item>
    <item>
      <title>GHSA-jwc3-6qvm-4r66</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jwc3-6qvm-4r66</link>
      <description>&lt;p&gt;In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jwc3-6qvm-4r66</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-73282 — In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding opera…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-73282</link>
      <description>msrc_CVE-2026-73282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-73282</guid>
    </item>
    <item>
      <title>OESA-2026-3746 — openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3746</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: openssh&lt;/p&gt;
&lt;p&gt;An open source implementation of SSH protocol version 2&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.(CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.(CVE-2026-73283)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: openssh&lt;/p&gt;
&lt;p&gt;An open source implementation of SSH protocol version 2&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.(CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.(CVE-2026-73283)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3746</guid>
    </item>
    <item>
      <title>RHSA-2026:69129 — Red Hat Security Advisory: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:69129</link>
      <description>&lt;p&gt;openssh: OpenSSH: sftp client allows attacker to control downloaded file location openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options openssh: OpenSSH: ssh-agent allows remote execution of local operations openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client openssh: OpenSSH: Tunnel forwarding restriction bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssh: OpenSSH: sftp client allows attacker to control downloaded file location openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options openssh: OpenSSH: ssh-agent allows remote execution of local operations openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client openssh: OpenSSH: Tunnel forwarding restriction bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:69129</guid>
    </item>
    <item>
      <title>RHSA-2026:70719 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:70719</link>
      <description>&lt;p&gt;openssh: OpenSSH: ssh-agent allows remote execution of local operations openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client openssh: OpenSSH: Tunnel forwarding restriction bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssh: OpenSSH: ssh-agent allows remote execution of local operations openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client openssh: OpenSSH: Tunnel forwarding restriction bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:70719</guid>
    </item>
    <item>
      <title>RLSA-2026:69129 — Important: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:69129</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssh&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: sftp client allows attacker to control downloaded file location (CVE-2026-59995)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options (CVE-2026-59999)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Tunnel forwarding restriction bypass (CVE-2026-73283)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: ssh-agent allows remote execution of local operations (CVE-2026-73281)&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client (CVE-2026-73282)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:69129</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-73282</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73282</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssh, Ubuntu:Pro:16.04:LTS: openssh, Ubuntu:Pro:FIPS:16.04:LTS: openssh, Ubuntu:Pro:18.04:LTS: openssh, Ubuntu:18.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssh, Ubuntu:Pro:FIPS:18.04:LTS: openssh, Ubuntu:Pro:20.04:LTS: openssh, Ubuntu:20.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:20.04:LTS: openssh and 10 more&lt;/p&gt;
&lt;p&gt;In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssh, Ubuntu:Pro:16.04:LTS: openssh, Ubuntu:Pro:FIPS:16.04:LTS: openssh, Ubuntu:Pro:18.04:LTS: openssh, Ubuntu:18.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssh, Ubuntu:Pro:FIPS:18.04:LTS: openssh, Ubuntu:Pro:20.04:LTS: openssh, Ubuntu:20.04:LTS: openssh-ssh1, Ubuntu:Pro:FIPS-updates:20.04:LTS: openssh and 10 more&lt;/p&gt;
&lt;p&gt;In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-73282</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2747 — OpenSSH: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2747</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial of Service und potentiell Codeausführung zu erreichen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um Sicherheitsvorkehrungen zu umgehen, einen Denial of Service und potentiell Codeausführung zu erreichen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2747</guid>
    </item>
  </channel>
</rss>
