CVE-2025-26465

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Feb 18, 2025
Updated: Mar 3, 2025
CWE ID 390

Summary

CVE-2025-26465 is a vulnerability affecting OpenSSH when the VerifyHostKeyDNS option is enabled. In this scenario, a man-in-the-middle attack is possible, with a malicious server impersonating a legitimate one. The attack arises due to OpenSSH's mishandling of error codes during host key verification under specific conditions. To execute a successful attack, an attacker must first exhaust the client's memory resources, making the attack complexity high.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share