CVE-2026-35414
OpenBSD OpenSSH, openssh
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
- CVSS
- 8.1
- EPSS
- 0.18% 7.33% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.03