CVE-2026-73283: Low severity OpenSSH sshd vulnerability
In sshd in OpenSSH before 10.5, the restrict keyword (in authorizedkeys) was supposed to be applicable to tunnel forwarding but was not.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:10.5p1-1 - Upgrade
Upgrade
debian/openssh-gssapito a version that resolves this vulnerability.Fixed in 1:10.5p1-1 - Upgrade
Upgrade
OpenSSH (sshd)to a version that resolves this vulnerability.Fixed in 10.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73283?
The severity of CVE-2026-73283 is rated as low with a score of 2.5.
How do I fix CVE-2026-73283?
To fix CVE-2026-73283, update your OpenSSH installation to version 10.5 or later.
What software is affected by CVE-2026-73283?
CVE-2026-73283 affects OpenSSH sshd prior to version 10.5.
What does the restrict keyword issue in CVE-2026-73283 affect?
The restrict keyword issue in CVE-2026-73283 affects tunnel forwarding in OpenSSH.
When was CVE-2026-73283 published?
CVE-2026-73283 was published on August 11, 2026.