internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssh | Sep 1, 2026 | Jul 8, 2026 |
| Ibm Aix | — | Apply the fix or workaround for aix_vios_advisory | Aug 16, 2026 | Aug 14, 2026 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 10.4 | Aug 18, 2026 | Jul 8, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jul 8, 2026 |
| Ubuntu | — | Upgrade openssh-clientUpgrade openssh-server | Jul 13, 2026 | Jul 8, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 22, 2026 | Jul 8, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub