Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4584-1 | openssh security update |
Ubuntu USN |
USN-8222-1 | OpenSSH vulnerabilities |
Sat, 04 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OpenSSH Authorized Keys Principal Parsing Vulnerability with Comma Characters | OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option |
| Weaknesses | CWE-168 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OpenSSH Authorized Keys Principal Parsing Vulnerability with Comma Characters |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters. | |
| First Time appeared |
Openbsd
Openbsd openssh |
|
| Weaknesses | CWE-670 | |
| CPEs | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openbsd
Openbsd openssh |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-02T18:17:04.391Z
Reserved: 2026-04-02T17:08:15.208Z
Link: CVE-2026-35414
Updated: 2026-04-02T17:43:15.738Z
Status : Analyzed
Published: 2026-04-02T18:16:34.690
Modified: 2026-04-10T19:36:57.163
Link: CVE-2026-35414
OpenCVE Enrichment
Updated: 2026-04-07T07:55:53Z
Debian DLA
Ubuntu USN