Description
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Published: 2026-07-08
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SSH in OpenSSH versions prior to 10.4 contains a use‑after‑free bug that is triggered when a server changes its host key during a key exchange. The bug causes the client to dereference a freed memory pointer, resulting in a crash. This vulnerability is mapped to CWE‑416 and CWE‑825 and manifests as a denial‑of‑service condition on the client side.

Affected Systems

The affected component is the OpenBSD OpenSSH client. All installations running a version earlier than 10.4 are vulnerable. Derived packages or distributions that have not updated to 10.4p1 or later share this issue.

Risk and Exploitability

The CVSS score of 7.7 reflects a high severity for a client‑side denial of service. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, suggesting no widely reported attacks. The likely attack vector is remote; an attacker who can control an SSH server can trigger the fault by changing its host key during a session. Exploitation requires network connectivity to the vulnerable client and the ability to alter the host key on the server side. No known remote code execution path exists.

Generated by OpenCVE AI on July 26, 2026 at 18:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenSSH client to version 10.4p1 or later.
  • Enable StrictHostKeyChecking to detect and prevent silent acceptance of new host keys.
  • Apply vendor security updates promptly and monitor OpenSSH releases for new patches.

Generated by OpenCVE AI on July 26, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8533-1 OpenSSH vulnerabilities
History

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Wed, 08 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
First Time appeared Openbsd
Openbsd openssh
Weaknesses CWE-416
CPEs cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Vendors & Products Openbsd
Openbsd openssh
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T13:02:27.583Z

Reserved: 2026-07-08T00:17:32.675Z

Link: CVE-2026-60002

cve-icon Vulnrichment

Updated: 2026-07-08T13:02:05.356Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-08T00:17:33Z

Links: CVE-2026-60002 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T18:45:03Z

Weaknesses