OpenSSH 10.3 Fixes Shell Injection and Multiple SSH Security Issues
ID: 90e6e5b9-2d13-58c7-b3e6-cf9fd76dfb25
STIX ID: report--90e6e5b9-2d13-58c7-b3e6-cf9fd76dfb25
Feed Name: cybersecurityNews.com
OpenSSH 10.3 (released April 2, 2026) patches a shell-injection vulnerability in the -J/ProxyJump command-line option, tightens validation of certificate principals (preventing empty-principals from acting as wildcards and clarifying wildcard support), and removes backward-compatibility for implementations that do not support transport-layer rekeying; administrators should prioritize updating, review any programmatically constructed ProxyJump inputs and existing CA-issued certificates, and obtain the release from official mirrors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
