| Bug | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-78662 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Previously, a channel registered in the mux's chanList is not usable u ... |
| CVE-2026-56855 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Previously, after a channel has been established, a malicious peer cou ... |
| CVE-2026-56854 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | The source-address critical option in the Permissions returned by an a ... |
| CVE-2026-46598 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | For certain crafted inputs, a 'ed25519.PrivateKey' was created by cast ... |
| CVE-2026-46597 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | An incorrectly placed cast from bytes to int allowed for server-side p ... |
| CVE-2026-46595 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Previously, CVE-2024-45337 fixed an authorization bypass for misused s ... |
| CVE-2026-42508 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Previously, a revoked 'SignatureKey' belonging to a CA was not correct ... |
| CVE-2026-39835 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | SSH servers which use CertChecker as a public key callback without set ... |
| CVE-2026-39834 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | When writing data larger than 4GB in a single Write call on an SSH cha ... |
| CVE-2026-39833 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | The in-memory keyring returned by NewKeyring() silently accepted keys ... |
| CVE-2026-39832 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | When adding a key to a remote agent constraint extensions such as rest ... |
| CVE-2026-39831 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ... |
| CVE-2026-39830 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | A malicious SSH peer could send unsolicited global request responses t ... |
| CVE-2026-39829 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | The RSA and DSA public key parsers did not enforce size limits on key ... |
| CVE-2026-39828 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | When an SSH server authentication callback returned PartialSuccessErro ... |
| CVE-2026-39827 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | An authenticated SSH client that repeatedly opened channels which were ... |
| CVE-2025-58181 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | SSH servers parsing GSSAPI authentication requests do not validate the ... |
| CVE-2025-47914 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | SSH Agent servers do not validate the size of messages when processing ... |
| CVE-2025-47913 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed respons ... |
| CVE-2025-22869 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | SSH servers which implement file transfer protocols are vulnerable to ... |
| CVE-2024-45337 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Applications and libraries which misuse connection.serverAuthenticate ... |
| CVE-2023-48795 | vulnerable (no DSA) | fixed | fixed | fixed | The SSH transport protocol with certain OpenSSH extensions, found in O ... |