CVE-2026-73282: OpenBSD OpenSSH
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
Affected products
- OpenBSD OpenSSH: before 10.5 (fixed in 10.5)
Published 2026-08-11. Last modified 2026-09-04.