VDB

GCVE-VVD-MAGEIA-2026-59

GCVE-VVD-MAGEIA-2026-59
Advisory Published
Vulnetix · Advisory published March 19, 2026
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used. The untrusted sources are the command line and %-sequence expansion of a configuration file. (CVE-2025-61984) ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used. (CVE-2025-61985)

Affected Products

VendorProductVersionsPlatforms
Mageiaopenssh0 (affected), 9.3p1-2.6.mga9 (unaffected), 0 (affected), 9.3p1-2.6.mga9 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›