Description
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
Published: 2026-05-25
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PuTTY versions 0.72 through 0.83 contain a double free bug in the RSA key exchange routine. The vulnerability manifests when the client releases memory twice while processing the RSA parameters received from the server, causing heap corruption. If an attacker can control these parameters, they may exploit the corruption to gain arbitrary code execution or cause a denial of service by crashing the client. The core weakness is reflected in CWE‑415.

Affected Systems

The affected products are PuTTY version 0.72, 0.73, 0.74, 0.75, 0.76, 0.77, 0.78, 0.79, 0.80, 0.81, 0.82, and 0.83. Any system using one of these releases as the SSH client is vulnerable; the next major release, 0.84, contains the fix.

Risk and Exploitability

The CVSS score of 3.7 indicates moderate severity, and no EPSS score is currently published, so the likelihood of exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. The likely attack vector is remote, stemming from an SSH connection with a malicious server, as the issue is triggered during the RSA key exchange process. Without an automated exploitation tool, the risk remains relatively low but still significant enough to warrant a patch.

Generated by OpenCVE AI on May 25, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PuTTY to version 0.84 or later, where the double free is fixed.
  • Reconfigure the SSH server to disable RSA key exchange or force a safer key exchange algorithm such as Diffie–Hellman or Elliptic Curve methods.
  • Monitor client logs and system stability for crashes or abnormal terminations that may indicate unpatched exploitation attempts.

Generated by OpenCVE AI on May 25, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 21:45:00 +0000

Type Values Removed Values Added
Title PuTTY RSA Key Exchange Double-Free Vulnerability

Mon, 25 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description PuTTY 0.72 before 0.84 has a double free in RSA KEX.
First Time appeared Putty
Putty putty
Weaknesses CWE-415
CPEs cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:*
Vendors & Products Putty
Putty putty
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-25T20:13:58.605Z

Reserved: 2026-05-25T20:13:58.149Z

Link: CVE-2026-48850

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T22:30:15Z

Weaknesses