CVE-2021-41617High· 7.0▾ MidnightPoC availablesshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and Authoriz…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 38.5 · likelihood 0.5 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.4%
2.4% → 2.5%
1 GitHub repo
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
openssh >= 6.2, < 8.8fedora = 33fedora = 34fedora = 35active_iq_unified_managerclustered_data_ontaphci_management_nodeontap_select_deploy_administration_utilitysolidfireaff_a250_firmwareaff_500f_firmwarehttp_server = 12.2.1.2.0http_server = 12.2.1.3.0http_server = 12.2.1.4.0zfs_storage_appliance_kit = 8.8starwind_virtual_san = v8r13Upgrade past the affected range:
openssh 8.8Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-51384Medium· 5.5In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied
CVE-2023-28531Critical· 9.8ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints
CVE-2024-6387High· 8.1A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd)
CVE-2025-26465Medium· 6.8A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled
CVE-2025-61984Low· 3.6ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand is used
CVE-2025-61985Low· 3.6ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.