Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
OpenSSH 10.4 or earlier: Host Key Change Security Risk
published 21 days ago
Summary
Older versions of OpenSSH may allow a server to bypass security checks when its host key is changed. This is a security risk for users who connect to servers with OpenSSH. To stay secure, update to OpenSSH 10.4 or later.
What to do
- Update openssh_jll to version 10.4.1+0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Julia | – | openssh_jll |
< 10.4.1+0 Fix: upgrade to 10.4.1+0
|
Original advisory text
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a...
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Severity
9.4
Critical
CVSS 3.1: 9.4 (OSV)
Timeline
Published14 Aug 2026
Updated14 Aug 2026
First seen14 Aug 2026
Sources
JLSEC-2026-1326 · OSV
Monitor software like this
Free during beta