VDB

JLSEC-2026-64

JLSEC-2026-64 PUBLISHED CVSS 4.599999904632568 MEDIUM

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

Risk Scores

CVSS 2.0
4.599999904632568

Affected Products

VendorProductVersions
JuliaOpenSSH_jll8.9.0+0
JuliaOpenSSH_jll8.9.0+0, 8.9.0+0

Timeline

  • Apr 9, 2026 CVE Published
  • Jul 18, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›