Sploitus

CVE-2025-26465

9 known exploits for CVE-2025-26465

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

Openbsd Openssh
≀ 9.8, 6.8, 9.9
Fix
Available
CVSS 3.1
6.8 MEDIUM
EPSS
7.6% (94th percentile)
Weakness
CWE-390
NVD status
Modified
Published
2025-02-18

Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

CVE-2025-26465 at NVD
Authoritative description, scoring and affected products

9 known exploits for CVE-2025-26465

Proof-of-concept code and exploit modules indexed by Sploitus