Openbsd
21 known vulnerabilities
Top Products
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u
sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a c
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group
OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function wi
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values f
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Dis
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list i
OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or H
In OpenSSH before 10.3, command execution can occur via shell metacharacters in a username within a command line. This r
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' e
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI
Frequently Asked Questions
How many CVEs affect Openbsd?
Openbsd has 21 CVE records in our database, including 0 critical and 4 high severity vulnerabilities.
What are the most severe Openbsd vulnerabilities?
Openbsd has 0 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Openbsd vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Openbsd products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Openbsd Vulnerabilities
CyberStrike scans your infrastructure for Openbsd vulnerabilities and provides real-time remediation guidance.
Get Started