Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-60002: OpenSSH Server Key Change Causes Client Crash

CVE-2026-60002 CVE-2026-60002
Summary

OpenSSH servers before version 10.4 can crash connected clients if their host key is changed during a secure connection. This could potentially be exploited by an attacker, but only if they have already compromised the server. To fix this, update to OpenSSH 10.4 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
openbsd openssh < 10.4
Original title
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Original description
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
nvd CVSS3.1 7.7
Vulnerability type
CWE-416 Use After Free
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026