Home
MEDIUM: 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
Any version before 10.3
affected
Description
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
Problem types
CWE-670 Always-Incorrect Control Flow Implementation
Product status
Any version before 10.3
References
www.openssh.org/releasenotes.html
marc.info/?l=openssh-unix-dev&m=177513443901484&w=2
www.openwall.com/lists/oss-security/2026/04/02/3