Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-60002: OpenSSH Server Key Change Causes Client Crash
CVE-2026-60002
CVE-2026-60002
Summary
OpenSSH servers before version 10.4 can crash connected clients if their host key is changed during a secure connection. This could potentially be exploited by an attacker, but only if they have already compromised the server. To fix this, update to OpenSSH 10.4 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| openbsd | openssh | < 10.4 |
Original title
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
Original description
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
nvd CVSS3.1
7.7
Vulnerability type
CWE-416
Use After Free
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026