Overview
What is CVE-2026-73283?
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
Vulnerability intelligence
CVE-2026-73283 and is rated Low severity with a CVSS score of 2.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.