OpenSSH Vulnerability in ECDSA Algorithm Interpretation by OpenSSH
CVE-2026-35387

3.1LOW

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
2 April 2026

What is CVE-2026-35387?

The vulnerability involves OpenSSH versions prior to 10.3, which inadequately handles certain ECDSA algorithms. Specifically, when any ECDSA algorithm is listed in the configuration options 'PubkeyAcceptedAlgorithms' or 'HostbasedAcceptedAlgorithms', it is erroneously interpreted to mean that all ECDSA algorithms are accepted. This misinterpretation can lead to unintended security implications, potentially allowing unauthorized access or facilitating attacks that exploit improperly validated algorithm types.

Affected Version(s)

OpenSSH 0 < 10.3

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.