OpenSSH Vulnerability in ECDSA Algorithm Interpretation by OpenSSH
CVE-2026-35387
3.1LOW
What is CVE-2026-35387?
The vulnerability involves OpenSSH versions prior to 10.3, which inadequately handles certain ECDSA algorithms. Specifically, when any ECDSA algorithm is listed in the configuration options 'PubkeyAcceptedAlgorithms' or 'HostbasedAcceptedAlgorithms', it is erroneously interpreted to mean that all ECDSA algorithms are accepted. This misinterpretation can lead to unintended security implications, potentially allowing unauthorized access or facilitating attacks that exploit improperly validated algorithm types.
Affected Version(s)
OpenSSH 0 < 10.3