logo

OpenSSH 10.3 Fixes Shell Injection and Multiple SSH Security Issues

ID: 90e6e5b9-2d13-58c7-b3e6-cf9fd76dfb25

STIX ID: report--90e6e5b9-2d13-58c7-b3e6-cf9fd76dfb25

Feed Name: cybersecurityNews.com

Threat Score
50/100

Date Published: 2026-04-02

Date Updated: 2026-04-21

Author: Guru Baran

...
...

OpenSSH 10.3 (released April 2, 2026) patches a shell-injection vulnerability in the -J/ProxyJump command-line option, tightens validation of certificate principals (preventing empty-principals from acting as wildcards and clarifying wildcard support), and removes backward-compatibility for implementations that do not support transport-layer rekeying; administrators should prioritize updating, review any programmatically constructed ProxyJump inputs and existing CA-issued certificates, and obtain the release from official mirrors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.