Home
LOW: 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:NDefault status
unaffected
Any version before 10.3
affected
Description
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
Problem types
CWE-420 Unprotected Alternate Channel
Product status
Any version before 10.3
References
www.openssh.org/releasenotes.html
marc.info/?l=openssh-unix-dev&m=177513443901484&w=2
www.openwall.com/lists/oss-security/2026/04/02/3