OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
References
Configurations
No configuration.
History
02 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 17:16
Updated : 2026-04-03 16:10
NVD link : CVE-2026-35387
Mitre link : CVE-2026-35387
CVE.ORG link : CVE-2026-35387
JSON object : View
Products Affected
No product.
CWE
CWE-670
Always-Incorrect Control Flow Implementation
