https://seclists.org/oss-sec/2026/q1/312: Some telnet clients leak environment variables
Published Mar 14, 2026
·Updated
Affected Software
4 affected components
OpenBSD OpenBSD
redhat/telnet
gentoo/telnet-bsd
openwrt/telnet-bsd
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
CVE-2026-XXXX is considered a medium severity vulnerability due to the potential leakage of sensitive environment variables.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, ensure that your telnet client is updated to the latest version that addresses this leakage issue.
3
Which software is affected by CVE-2026-XXXX?
CVE-2026-XXXX affects telnet clients in OpenBSD 7.8, Red Hat, Gentoo, and OpenWRT.
4
What sensitive variables are leaked in CVE-2026-XXXX?
CVE-2026-XXXX leaks potentially sensitive variables such as DISPLAY, XAUTHORITY, and PRINTER.
5
Is there a workaround for CVE-2026-XXXX?
A temporary workaround for CVE-2026-XXXX is to avoid using telnet with sensitive environment variables set.