logo

OpenSSH 10.3 Released With Patch for Shell Injection and Other Security Flaws

ID: daaea23d-9d09-539e-ad79-691240e8dd13

STIX ID: report--daaea23d-9d09-539e-ad79-691240e8dd13

Feed Name: GBHackers

Threat Score
55/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Divya

...
...

OpenSSH 10.3 (portable 10.3p1) was released to address several security issues, including a critical SSH client shell-injection vulnerability that could allow arbitrary command execution via crafted usernames and configuration tokens, a certificate authentication bypass with comma-separated names, legacy scp setuid/setgid permission issues, and an ECDSA key enforcement bug. The release also adds administrative features (connection inspection commands, invaliduser penalties, multiple revocation files, standardized agent forwarding, and sub-second penalties) and tightens hostname/username validation; administrators are advised to upgrade promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.