logo

New OpenSSH flaws expose SSH servers to MiTM and DoS attacks

ID: f22542c5-7d35-53b6-b07c-cddd60356d4d

STIX ID: report--f22542c5-7d35-53b6-b07c-cddd60356d4d

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-02-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

OpenSSH released version 9.9p2 fixing two vulnerabilities disclosed by Qualys: CVE-2025-26465, a decade-old client-side MitM that can bypass host-key verification when VerifyHostKeyDNS is enabled by inducing out-of-memory conditions with oversized keys/certificate extensions, and CVE-2025-26466, a pre-authentication DoS caused by uncontrolled buffering during key exchange; administrators are advised to upgrade, disable VerifyHostKeyDNS unless needed, and apply connection-rate protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.