CVE-2026-106586 — In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a differe…
Description
In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not, a different vulnerability than CVE-2026-73283.
CVSS v3.1 base metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:NLow severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
High
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
Low
Integrity
A
None
Availability
Related threats
same CWE or vendorCVE-2026-107284 — The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses.
CVE-2026-107284 · 1d ago
CVE-2026-102124 — A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration.
CVE-2026-102124 · 8d ago
CVE-2026-102110 — An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so du…
CVE-2026-102110 · 8d ago
CVE-2026-98164 — In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address spaces kvm_gfn_is_write_tra…
CVE-2026-98164 · 9d ago
CVE-2026-96760 — Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability.
CVE-2026-96760 · 10d ago
CVE-2026-98051 — In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times The loop ini…
CVE-2026-98051 · 14d ago