Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-55653

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 10.0%
CVSS Severity
CVSS v3 Score 4.3


Contact Us

Shodan ® - All rights reserved