Overview
What is CVE-2026-73282?
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
Vulnerability intelligence
CVE-2026-73282 and is rated Medium severity with a CVSS score of 4.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.