Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

OpenSSH 10.4 or earlier: Host Key Change Security Risk

published 21 days ago
Summary

Older versions of OpenSSH may allow a server to bypass security checks when its host key is changed. This is a security risk for users who connect to servers with OpenSSH. To stay secure, update to OpenSSH 10.4 or later.

What to do
  • Update openssh_jll to version 10.4.1+0.
Affected software
Ecosystem VendorProductAffected versions
Julia – openssh_jll < 10.4.1+0
Fix: upgrade to 10.4.1+0
Original advisory text
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a...
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Severity
9.4 Critical
CVSS 3.1: 9.4 (OSV)
Timeline
Published14 Aug 2026
Updated14 Aug 2026
First seen14 Aug 2026
Sources
Monitor software like this
Free during beta