CVE-2020-36254: Dropbear SSH Project Dropbear SSH

High severity, CVSS 8.1. EPSS: 1.9% chance of exploitation in the next 30 days.

scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.

Affected products

Published 2021-02-25. Last modified 2026-06-17.