Home
LOW: 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:NDefault status
unaffected
Any version before 10.3
affected
Description
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
Problem types
CWE-670 Always-Incorrect Control Flow Implementation
Product status
Any version before 10.3
References
www.openssh.org/releasenotes.html
marc.info/?l=openssh-unix-dev&m=177513443901484&w=2
www.openwall.com/lists/oss-security/2026/04/02/3