AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-26465

MEDIUM · CVSS 6.8 EPSS 7.45%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-02-18 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.8. See the original NVD description below for full technical details.

CVE
CVE-2025-26465
Severity
MEDIUM
CVSS
6.8
EPSS
7.45%

Original NVD Description

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.

Related CVEs

Other vulnerabilities affecting the same vendor(s)