CVE-2026-73283 - Low Severity Vulnerability
Vulnerable Library - src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Found in base branches: stable/4.0, master
Vulnerable Source Files (1)
/crypto/openssh/serverloop.c
Vulnerability Details
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
Publish Date: 2026-08-11
URL: CVE-2026-73283
CVSS 3 Score Details (2.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-11
Fix Resolution: https://github.com/openssh/openssh-portable.git - V_10_5_P1
Step up your Open Source Security Game with Mend here
CVE-2026-73283 - Low Severity Vulnerability
Library home page: https://github.com/MidnightBSD/src.git
Found in base branches: stable/4.0, master
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
Publish Date: 2026-08-11
URL: CVE-2026-73283
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-08-11
Fix Resolution: https://github.com/openssh/openssh-portable.git - V_10_5_P1
Step up your Open Source Security Game with Mend here