CVE detail
CVE-2025-26465
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
34 source links · newest first
- Siemens SIDIS Secured SmartPlugCISA Alerts
l Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2022-23303 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-
governmentwww.cisa.govJul 21, 2026, 12:00 PM The flaws could allow a remote attacker to maintain access after their account has been disabled and to access information from other user sessions.
newswww.securityweek.comApr 15, 2026, 11:38 AMCISOs need to lean on their admins to plug zero day vulnerabilities in Windows and VMware products as soon as possible, before they are widely exploited. In addition, Windows admins need to be aware of a vulnerability that already has a publicly-available proof of concept exploit that threat actors are sure to jump on. Finally, […]
newswww.csoonline.comMar 12, 2025, 12:15 AMA new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Lazarus APT stole $1.5B from Bybit, it is the largest cryptocurrency heist ever Apple removes iCloud encryption in […]
newssecurityaffairs.comFeb 23, 2025, 12:38 PMThe latest OpenSSH update patches two vulnerabilities, including one that enabled MitM attacks with no user interaction.
newswww.securityweek.comFeb 19, 2025, 1:32 PM- OpenSSH bugs allows Man-in-the-Middle and DoS AttacksSecurity Affairs
Two OpenSSH vulnerabilities could allow machine-in-the-middle (MitM) and denial-of-service (DoS) attacks under certain conditions. The Qualys Threat Research Unit (TRU) has discovered two vulnerabilities in OpenSSH. The first, tracked as CVE-2025-26465 (CVSS score: 6.8) can be exploited by an attacker to conduct an active machine-in-the-middle attack on the OpenSSH client when the VerifyHostKeyDNS option is enabled. The […]
newssecurityaffairs.comFeb 19, 2025, 12:10 PM OpenSSH, the most widely used tool for remotely managing Linux and BSD systems, received patches for two vulnerabilities. One of the flaws could allow attackers to perform a man-in-the-middle attack against OpenSSH clients with a certain configuration and impersonate a server to intercept sensitive communications. While the second vulnerability can lead to CPU resource exhaustion. […]
newswww.csoonline.comFeb 18, 2025, 10:59 PM- https://cert-portal.siemens.com/productcert/html/ssa-585531.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comFeb 18, 2025, 7:15 PM - https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comFeb 18, 2025, 7:15 PM No excerpt available.
Exploitwww.vicarius.ioFeb 18, 2025, 7:15 PMNo excerpt available.
Exploitwww.vicarius.ioFeb 18, 2025, 7:15 PM- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/www.theregister.com
No excerpt available.
Third Party Advisorywww.theregister.comFeb 18, 2025, 7:15 PM - https://www.openwall.com/lists/oss-security/2025/02/18/4www.openwall.com
No excerpt available.
Exploitwww.openwall.comFeb 18, 2025, 7:15 PM - https://www.openwall.com/lists/oss-security/2025/02/18/1www.openwall.com
No excerpt available.
Exploitwww.openwall.comFeb 18, 2025, 7:15 PM - https://www.openssh.com/releasenotes.html#9.9p2www.openssh.com
No excerpt available.
Vendor Advisorywww.openssh.comFeb 18, 2025, 7:15 PM No excerpt available.
Third Party Advisoryubuntu.comFeb 18, 2025, 7:15 PM- https://security.netapp.com/advisory/ntap-20250228-0003/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comFeb 18, 2025, 7:15 PM - https://security-tracker.debian.org/tracker/CVE-2025-26465security-tracker.debian.org
No excerpt available.
Third Party Advisorysecurity-tracker.debian.orgFeb 18, 2025, 7:15 PM - https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.htmllists.mindrot.org
No excerpt available.
Third Party Advisorylists.mindrot.orgFeb 18, 2025, 7:15 PM No excerpt available.
Vendor Advisorylists.debian.orgFeb 18, 2025, 7:15 PMNo excerpt available.
Patchftp.openbsd.orgFeb 18, 2025, 7:15 PM- https://bugzilla.suse.com/show_bug.cgi?id=1237040bugzilla.suse.com
No excerpt available.
Exploitbugzilla.suse.comFeb 18, 2025, 7:15 PM No excerpt available.
Mitigationblog.qualys.comFeb 18, 2025, 7:15 PM- http://seclists.org/fulldisclosure/2025/May/8seclists.org
No excerpt available.
Exploitseclists.orgFeb 18, 2025, 7:15 PM - http://seclists.org/fulldisclosure/2025/May/7seclists.org
No excerpt available.
Exploitseclists.orgFeb 18, 2025, 7:15 PM - http://seclists.org/fulldisclosure/2025/Feb/18seclists.org
No excerpt available.
Exploitseclists.orgFeb 18, 2025, 7:15 PM - https://seclists.org/oss-sec/2025/q1/144seclists.org
No excerpt available.
Exploitseclists.orgFeb 18, 2025, 7:15 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2344780bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comFeb 18, 2025, 7:15 PM - https://access.redhat.com/solutions/7109879access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 18, 2025, 7:15 PM - https://access.redhat.com/security/cve/CVE-2025-26465access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 18, 2025, 7:15 PM - https://access.redhat.com/errata/RHSA-2025:8385access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 18, 2025, 7:15 PM - https://access.redhat.com/errata/RHSA-2025:6993access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 18, 2025, 7:15 PM - https://access.redhat.com/errata/RHSA-2025:3837access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 18, 2025, 7:15 PM - https://access.redhat.com/errata/RHSA-2025:16823access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 18, 2025, 7:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2020-15707CVSS 5.7 · Medium
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the function…
- CVE-2019-14379CVSS 9.8 · Critical
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransaction…
- CVE-2024-12086CVSS 6.1 · Medium
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a c…
- CVE-2026-55653CVSS 4.3 · Medium
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Fed…
- CVE-2026-31431CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the…
- CVE-2026-3497CVSS 6.9 · Medium
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not…