CVE-2026-73283
published 2026-08-11CVE-2026-73283: In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
PriorityP411low2.5CVSS 3.1
AVLACHPRLUINSUCNILAN
EPSS
0.09%
0.5th percentile
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openbsd | openssh | < 10.5 | 10.5 |
| openbsd | openssh | — | — |
| ubuntu | openssh | — | — |
CVSS provenance
nvdv3.12.5LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
vendor_ubuntu3.5LOW
vendor_redhat2.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
ghsa_unreviewed·2026-08-11
CVE-2026-73283 [LOW] CWE-670 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2026-09-03·CVSS 3.5
CVE-2026-73281 [LOW] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH's ssh-agent incorrectly handled interactions
between agent locking and the [email protected] extension. A remote
attacker with access to a forwarded agent connection could possibly use
this issue to perform operations that should only be available locally,
such as adding tokens or using keys. (CVE-2026-73281)
It was discovered that OpenSSH's ssh client incorrectly handled concurrent
remote-forwarding operations. A remote attacker could possibly use this
issue to cause a use-after-free condition, resulting in a denial of service
or the execution of arbitrary code. (CVE-2026-73282)
It was discovered that OpenSSH's sshd server incorrectly applied the
restrict keywor
Red Hat
openssh: OpenSSH: Tunnel forwarding restriction bypass
vendor_redhat·2026-08-11·CVSS 2.5
CVE-2026-73283 [LOW] CWE-305 openssh: OpenSSH: Tunnel forwarding restriction bypass
openssh: OpenSSH: Tunnel forwarding restriction bypass
A flaw was found in OpenSSH's `sshd` component. The `restrict` keyword, designed to limit tunnel forwarding within the `authorized_keys` file, was not correctly enforced for tunnel forwarding. This issue could allow a local attacker to bypass intended security restrictions, potentially leading to unauthorized network access or resource usage through tunnels.
Statement: An authorization bypass flaw was found in OpenSSH's sshd daemon. When processing SSH public key authentication, sshd fails to enforce the restrict keyword in authorized_keys against TUN/TAP tunnel forwarding requests. An authenticated user holding a restricted key can still establish virtual network interface tunnels if tunnel forwarding is globally enabled on the serv
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-73283 openssh: OpenSSH: Tunnel forwarding restriction bypass [fedora-all]
bugzilla·2026-08-17·CVSS 2.5
CVE-2026-73283 [LOW] CVE-2026-73283 openssh: OpenSSH: Tunnel forwarding restriction bypass [fedora-all]
CVE-2026-73283 openssh: OpenSSH: Tunnel forwarding restriction bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
Bugzilla
CVE-2026-73283 openssh: OpenSSH: Tunnel forwarding restriction bypass
bugzilla·2026-08-11·CVSS 2.5
CVE-2026-73283 [LOW] CVE-2026-73283 openssh: OpenSSH: Tunnel forwarding restriction bypass
CVE-2026-73283 openssh: OpenSSH: Tunnel forwarding restriction bypass
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
2026-08-11
Published