OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters. | |
| First Time appeared |
Openbsd
Openbsd openssh |
|
| Weaknesses | CWE-670 | |
| CPEs | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openbsd
Openbsd openssh |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-02T18:17:04.391Z
Reserved: 2026-04-02T17:08:15.208Z
Link: CVE-2026-35414
Updated: 2026-04-02T17:43:15.738Z
Status : Received
Published: 2026-04-02T18:16:34.690
Modified: 2026-04-02T18:16:34.690
Link: CVE-2026-35414
No data.
OpenCVE Enrichment
No data.
Weaknesses