Known vulnerabilities in openssh (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:openssh_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 18
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting openssh (Red Hat package) openssh (Red Hat package) is affected by 18 known vulnerabilities: 3 high, 4 medium, 11 low Critical High Medium Low

Vulnerabilities (18)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU128473 - Improper input validation
CVE-2026-35386
CWE-20 Low
No
No
8.0p1-7.el8_4.2, 8.0p1-15.el8_6.5, 8.0p1-20.el8_8.4, 8.0p1-29.el8_10, 8.7p1-30.el9_2.11, 8.7p1-45.el9_6.3, 8.7p1-49.el9_7, 9.9p1-7.el10_0.3, 9.9p1-14.el10_1 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 16 more
#VU128474 - Improper Access Control
CVE-2026-35414
CWE-284 Low
No
No
8.0p1-7.el8_4.2, 8.0p1-15.el8_6.5, 8.0p1-20.el8_8.4, 8.0p1-29.el8_10, 8.7p1-30.el9_2.11, 8.7p1-45.el9_6.3, 8.7p1-49.el9_7, 9.9p1-7.el10_0.3, 9.9p1-14.el10_1 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 24 more
#VU128475 - Improper Privilege Management
CVE-2026-35385
CWE-269 Low
No
No
5.3p1-125.el6_10.1, 7.4p1-23.el7_9.2, 8.0p1-7.el8_4.2, 8.0p1-15.el8_6.5, 8.0p1-20.el8_8.4, 8.0p1-29.el8_10, 8.7p1-30.el9_2.11, 8.7p1-45.el9_6.3, 8.7p1-49.el9_7, 9.9p1-7.el10_0.3, 9.9p1-14.el10_1 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 30 more
#VU128476 - Improper Access Control
CVE-2026-35387
CWE-284 Low
No
No
8.0p1-7.el8_4.2, 8.0p1-15.el8_6.5, 8.0p1-20.el8_8.4, 8.0p1-29.el8_10, 8.7p1-30.el9_2.11, 8.7p1-45.el9_6.3, 8.7p1-49.el9_7, 9.9p1-7.el10_0.3, 9.9p1-14.el10_1 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 17 more
#VU128477 - Improper Authorization
CVE-2026-35388
CWE-285 Low
No
No
8.0p1-7.el8_4.2, 8.0p1-15.el8_6.5, 8.0p1-20.el8_8.4, 8.0p1-29.el8_10, 8.7p1-30.el9_2.11, 8.7p1-45.el9_6.3, 8.7p1-49.el9_7, 9.9p1-7.el10_0.3, 9.9p1-14.el10_1 29.04.2026 SB2026042988
SB2026042990
SB2026042992
and 19 more
#VU124014 - Resource Management Errors
CVE-2026-3497
CWE-399 Low
No
No
8.0p1-7.el8_4.1, 8.0p1-20.el8_8.3, 8.7p1-13.el9_0.2, 8.7p1-30.el9_2.10, 8.7p1-38.el9_4.7, 8.7p1-45.el9_6.2, 9.9p1-7.el10_0.2 13.03.2026 SB2026031837
SB2026031838
SB2026031839
and 19 more
#VU116883 - Improper Neutralization of Null Byte or NUL Character
CVE-2025-61985
CWE-158 Low
No
No
8.0p1-27.el8_10, 8.7p1-13.el9_0.1, 8.7p1-30.el9_2.9, 8.7p1-38.el9_4.6, 8.7p1-45.el9_6.1, 9.9p1-7.el10_0.1 10.10.2025 SB2025101008
SB2025103199
SB20251031100
and 26 more
#VU116882 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-61984
CWE-78 Low
No
No
8.0p1-27.el8_10, 8.7p1-13.el9_0.1, 8.7p1-30.el9_2.9, 8.7p1-38.el9_4.6, 8.7p1-45.el9_6.1, 9.9p1-7.el10_0.1 10.10.2025 SB2025101008
SB2025103199
SB20251031100
and 28 more
#VU104035 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2025-26465
CWE-300 Medium
No
No
8.0p1-26.el8_10, 8.7p1-38.el9_4.5 18.02.2025 SB2025021815
SB2025021830
SB2025021833
and 49 more
#VU94522 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6409
CWE-362 High
No
No
8.7p1-12.el9_0.3, 8.7p1-30.el9_2.7, 8.7p1-38.el9_4.4 18.07.2024 SB2024070144
SB2024071838
SB20240718188
and 17 more
#VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2024-6387
CWE-362 High
Available
No
8.7p1-30.el9_2.4 01.07.2024 SB2024070144
SB2024070145
SB2024070152
and 89 more
#VU84789 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-51385
CWE-78 Medium
Available
No
8.0p1-7.el8_4.2, 8.0p1-19.el8_9.2, 8.7p1-13.el9_0.1, 8.7p1-34.el9_3.3 26.12.2023 SB2023121905
SB2023122710
SB2023122801
and 65 more
#VU84537 - Inadequate Encryption Strength
CVE-2023-48795
CWE-326 Low
Available
No
8.0p1-19.el8_9.2, 8.7p1-34.el9_3.3 19.12.2023 SB2023121903
SB2023121905
SB2023121906
and 343 more
#VU78454 - Untrusted Search Path
CVE-2023-38408
CWE-426 Medium
Available
No
5.3p1-125.el6_10, 7.4p1-23.el7_9, 8.0p1-5.el8_1.1, 8.0p1-5.el8_2, 8.0p1-7.el8_4, 8.0p1-15.el8_6, 8.0p1-19.el8_8, 8.7p1-11.el9_0, 8.7p1-30.el9_2 20.07.2023 SB2023072068
SB2023072073
SB2023072074
and 73 more
#VU71771 - Double Free
CVE-2023-25136
CWE-415 High
Available
No
8.7p1-29.el9_2 02.02.2023 SB2023020247
SB2023020304
SB2023021660
and 11 more
#VU58333 - Improper Privilege Management
CVE-2021-41617
CWE-269 Low
No
No
8.0p1-13.el8 23.11.2021 SB2021092601
SB2021112330
SB2021120119
and 38 more
#VU32937 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-14145
CWE-327 Medium
No
No
8.0p1-10.el8 30.07.2020 SB2020073043
SB2020121421
SB2021052625
and 11 more
#VU251 - Permissions, Privileges, and Access Controls
CVE-2015-8325
CWE-264 Low
No
No
6.6.1p1-31.el7 02.08.2016 SB2016080201
SB2016080202
SB2016080203
and 10 more